Derivation rules

2,433 declarative match → where → emit rules (1,787 derived, 646 explicit). Filter by cloud, emitted edge, node type, or text.

2,433 rule(s) · page 21 of 49

Storage Blob Data Reader/Contributor/Owner grants effective data-plane read of ADLS Gen2 content.
azure CanReadData derived
Storage Blob Data Contributor/Owner grants effective data-plane write of ADLS Gen2 content.
azure CanWriteData derived
generateUserDelegationKey/action allows minting user-delegation SAS tokens (Token credential type) for external distribution.
azure CanReadCredential derived
listKeys/action returns ADLS Gen2 account keys, bypassing all RBAC and ACLs.
azure CanReadCredential derived
Account key (from listKeys) grants full data-plane read and SAS generation - enabling complete data exfiltration.
azure CanExfiltrate derived
ADLS Gen2 account with public blob access enabled and a public container exposes blob data to unauthenticated internet access.
azure ExposedToInternet derived
Microsoft.ContainerService/managedClusters/* grants full control of the cluster (create/update/delete/stop/rotate/upgradeNodeImageVersion/etc.).
azure CanAdminister derived
A cluster-admin kubeconfig (from listClusterAdminCredential) grants kubectl exec into any pod in the cluster.
azure CanExecuteCommand derived
Cluster-admin kubeconfig -> exec any pod -> execute as every pod workload identity (cluster-wide summary edge; per-pod edges from container-chains cluster-rbac-exec).
azure CanExecuteAs derived
listClusterAdminCredential returns a static cluster-admin kubeconfig that bypasses AAD, giving unconditional cluster-admin access to the cluster.
azure CanReadCredential derived
listClusterUserCredential returns a user-level kubeconfig (AAD-token-gated, lower privilege), providing authenticated access to the cluster API server.
azure CanReadCredential derived
Node-level code execution (privileged pod, hostPID, DaemonSet exec) reaches the node IMDS and mints a token for the node system-assigned / kubelet MI.
azure CanExecuteAs derived
Azure Kubernetes Service RBAC Cluster Admin role (Azure RBAC mode) maps to k8s cluster-admin, granting kubectl exec on every pod.
azure CanExecuteCommand derived
A principal with roleAssignments/write or Owner role can grant the Azure Kubernetes Service RBAC Cluster Admin role to any principal.
azure CanGrantPermission derived
managedClusters/runCommand/action runs arbitrary kubectl/helm inside the cluster, bypassing network isolation; equivalent to cluster-wide kubectl exec.
azure CanExecuteCommand derived
runCommand grants cluster-wide kubectl exec; any pod's workload identity is reachable by exec-ing into the pod (container-chains cluster-rbac-exec).
azure CanExecuteAs derived
runCommand/action can kubectl-apply attacker manifests - new/patched Deployments - changing what code runs as each workload identity.
azure CanModifyCode derived
managedClusters/agentPools/write + assign on a target MI allows swapping the kubelet MI, binding all nodes to a more-privileged identity.
azure CanAttachIdentity derived
managedClusters/write can disable local account restrictions, change the OIDC issuer, swap kubelet MI, or alter network egress - configuration changes that unlock or change escalation paths.
azure CanModifyConfiguration derived
Submit a job to an AKS cluster attached as an AML compute target; the job runs inside the AKS cluster as a Kubernetes workload, enabling lateral movement to non-AML K8s resources.
azure CanModifyCode derived
Attach a user-assigned MI to an AML compute cluster/instance - future jobs run as the new MI.
azure CanAttachIdentity derived
Principal can invoke a batch endpoint to trigger a batch scoring job on the endpoint's compute cluster.
azure CanTrigger explicit
Overwrite a shared pipeline component definition; future pipeline jobs using that component run attacker code as the cluster MI.
azure CanModifyCode derived
Any code running on an AML compute node can mint the compute MI's token from IMDS - the MI credential is exposed to all job code.
azure ExposesCredential derived
Any code on an AML compute node can mint a bearer token for the compute MI via IMDS.
azure CanRetrieveToken derived
Write to a compute cluster - changes the compute identity block, SSH keys, subnet, or init scripts.
azure CanModifyConfiguration derived
Write access to a compute instance can modify SSH public key configuration and other network settings.
azure CanModifyConfiguration derived
SSH access to a running compute instance when SSH is enabled and the principal controls the SSH private key.
azure CanExecuteCommand explicit
Retrieve workspace connection secrets (API keys for OpenAI, Cognitive Services, or custom REST endpoints) via connections/listsecrets.
azure CanReadSecret derived
Create a new AML compute bound to a chosen user-assigned MI, then submit a job to it - execute as that MI.
azure CanCreateWorkloadAs derived
An AML datastore configured with accountKey/SAS/servicePrincipal credential exposes that credential to principals with listsecrets.
azure ExposesCredential derived
Retrieve stored datastore credentials (storage account key, SAS token, or SP client secret) via listsecrets.
azure CanReadSecret derived
move · open · esc close