Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Develop and execute adversary emulation tests on high-risk service principal permissions #1371

Open
1 task
mitchelbaker-cisa opened this issue Oct 22, 2024 · 0 comments
Labels
enhancement This issue or pull request will add new or improve existing functionality hands-on-prototyping Reviewing an M365 feature by performing hands-on prototyping
Milestone

Comments

@mitchelbaker-cisa
Copy link
Collaborator

💡 Summary

Refer to this list of high-risk service principal permissions. Determine the risk associated with assigning these permissions to a service principal, and determine what a malicious actor would have access to within an M365 environment.

Motivation and context

Associated with #1073 and builds on prototyping work for #1327.

Implementation notes

Use this issue as a reference point for reporting on information found.

Acceptance criteria

How do we know when this work is done?

@schrolla schrolla added this to the Kraken milestone Nov 4, 2024
@schrolla schrolla added enhancement This issue or pull request will add new or improve existing functionality hands-on-prototyping Reviewing an M365 feature by performing hands-on prototyping labels Nov 4, 2024
@schrolla schrolla modified the milestones: Kraken, Backlog Nov 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement This issue or pull request will add new or improve existing functionality hands-on-prototyping Reviewing an M365 feature by performing hands-on prototyping
Projects
None yet
Development

No branches or pull requests

2 participants