Extracting Sensitive Information from Azure Load Testing
netspi.com | blog | #cloud | #azure | #cloud-pentesting | #load-testing | #managed-identity | #key-vault | #jmeter | #locust
Summary
Azure Load Testing accepts JMeter JMX and Locust Python files that execute code in its environment, enabling Managed Identity token theft, reverse shells, and Key Vault secret extraction.
- Published
- Collected
Skip to content