Derivation rules

2,433 declarative match → where → emit rules (1,787 derived, 646 explicit). Filter by cloud, emitted edge, node type, or text.

2,433 rule(s) · page 29 of 49

A secret credential for a principal in another subscription yields entry there.
azure CanEnterSubscription derived
Reading a secret that is a credential for a more-privileged identity is escalation.
azure CanEscalateTo derived
A vault self-grant equally yields decrypt/unwrap on every key in the vault.
azure CanDecrypt derived
A vault self-grant yields read of every secret/cert in the vault.
azure CanReadSecret derived
A vault self-grant equally yields sign on every signing-capable key in the vault.
azure CanSignAs derived
Owner/User Access Admin self-assigns a Key Vault data-plane role (RBAC model).
azure CanGrantPermission derived
Attach a user-assigned managed identity to a Logic App (assign/action + workflows/write or sites/write).
azure CanAttachIdentity derived
Obtain the SAS-signed HTTP trigger callback URL for a Logic App (listCallbackUrl/action).
azure CanReadSecret derived
An API connection referencing a resource in a different subscription (same tenant) represents cross-subscription exposure.
azure ExposedToAccount derived
An API connection referencing a resource in a different Entra tenant represents cross-tenant credential trust.
azure CrossTenantTrust derived
An API connection stores a long-lived service credential (key/token) usable by any code that can call listConnectionKeys.
azure ExposesCredential derived
Full control of a Logic App workflow (Logic App Contributor / Contributor / Owner).
azure CanAdminister derived
A Logic App with a public HTTP (Request) trigger and no IP allowlist is triggerable from the internet.
azure ExposedToInternet derived
Invoke a Logic App HTTP trigger using a held callback URL (SAS-signed).
azure CanInvoke derived
A Standard Logic App with a bound MI exposes that MI's credential to any code/action running in the app.
azure ExposesCredential derived
Code/actions in a Standard Logic App can mint a bearer token for each bound MI via the App Service identity endpoint.
azure CanRetrieveToken derived
List the embedded key/token for an API connection used by a Logic App (listConnectionKeys/action).
azure CanReadSecret derived
A Logic App with a Recurrence trigger fires autonomously on a cadence - creating/modifying it with workflows/write is schedule creation.
azure CanSchedule derived
azure LocatedIn explicit
Read run-history expression traces containing secrets (API keys, connection strings, tokens) via listExpressionTraces/action.
azure CanReadSecret derived
Enable a disabled Logic App workflow to realize CONDITIONAL execution edges.
azure CanStart derived
Read decrypted app settings and connection strings of a Standard Logic App (config/list/Action).
azure CanReadSecret derived
Modify app settings/config of a Standard Logic App (WEBSITE_RUN_FROM_PACKAGE / image / env / identity).
azure CanModifyConfiguration derived
Deploy attacker code to a Standard Logic App via Kudu/SCM ZipDeploy (extensions/write).
azure CanModifyCode derived
Hijack the source control of a Standard Logic App to an attacker repo (sourcecontrols/Write).
azure CanModifyCode derived
Overwrite the Logic App workflow definition to inject arbitrary actions running as the workflow's MI.
azure CanModifyCode derived
Holding the Microsoft.Network/loadBalancers/* wildcard grants full control of a Standard Load Balancer.
azure CanAdminister derived
Writing a Load Balancer backend address pool allows adding an attacker-controlled VM to the pool, routing a fraction of traffic to it for interception or amplification.
azure CanModifyConfiguration derived
Creating or modifying an inbound NAT rule maps a public LB frontend port directly to a backend VM's port, potentially exposing SSH/RDP/admin ports to the internet.
azure CanModifyConfiguration derived
A Standard Load Balancer with a public frontend IP is reachable from the internet on its listener ports.
azure ExposedToInternet derived
Writing a Load Balancer resource allows adding a public frontend IP, new load-balancing rules, or inbound NAT rules that expose previously private ports.
azure CanModifyConfiguration derived
A customer principal with Microsoft.ManagedServices/registrationDefinitions/write can modify Lighthouse trust anchors (authorizations list, managing tenant).
azure CanModifyTrust derived
A customer principal with Microsoft.ManagedServices/registrationAssignments/write can create/modify Lighthouse registrationAssignments - enable cross-tenant access.
azure CanModify derived
A managing-tenant ExternalPrincipal named in a resource-group-scoped Lighthouse authorization has CanAdminister over that resource group.
azure CanAdminister derived
move · open · esc close