Azure-Bashing: Weaponizing Free Cloud Shells for Fun, Profit, and Persistence – Matt Poto Chris Ryan

The big three cloud providers (AWS, GCP, and Azure) all provide a cloud shell – an in-browser shell that lets administrators remotely manage their environment. While this sounds great, the trouble is that these cloud shells give out largely unmonitored resources, affording attackers a place to stealthily persist and launch attacks from trusted networking space. In this session, we will dive into the tactics, techniques, and procedures threat actors can use to weaponize a cloud shell, and demonstrate real attack chains built on our research. We won’t leave defenders out in the cold either, as we will talk about strategies for identifying cloud shell abuse and detection gaps, and potential mitigations. Defenders will gain an understanding of cloud shell abuse mechanisms, and what they can (and can’t!) monitor.