Skip to content
OPS // KITitspentest.sh

E-MIC

MicroBurst

PowerShell scripts for assessing Azure security — subdomain and storage enumeration, credential hunting in Automation accounts and App Services, and privilege-escalation checks.

Official siteBack to catalog

OVERVIEW

MicroBurst (github.com/NetSPI/MicroBurst) is a collection of PowerShell scripts, written and maintained by NetSPI, for assessing Microsoft Azure security. Rather than one monolithic tool, it is a modular toolkit — separate functions for subdomain enumeration, blob/file storage discovery, Automation account credential extraction, App Service configuration dumping, and Azure AD/RBAC privilege-escalation checks — that an assessor imports and runs selectively depending on what access has already been established.

Its Automation-account and App Service functions are the standout: Azure Automation runbooks and App Service application settings routinely end up holding plaintext credentials, connection strings, or certificates that were never meant to be broadly readable, and MicroBurst automates pulling and decoding them once an assessor has enough access to the resource to ask.

USE CASES

Practical use cases

  • 01

    Enumerating Azure subdomains and storage accounts associated with a target tenant.

  • 02

    Extracting plaintext credentials and certificates stashed in Azure Automation runbooks and variables.

  • 03

    Dumping App Service and Function App configuration to find exposed connection strings or secrets.

  • 04

    Running Azure AD and RBAC checks to surface common privilege-escalation paths for a given identity.

QUICK START

During an Azure assessment, to enumerate exposed storage and subdomains, hunt for credentials left in Automation runbooks or App Service configuration, and check common privilege-escalation paths.

  1. Clone the MicroBurst repository and import the module with `Import-Module .\MicroBurst.psm1`.
  2. Confirm the identity in use (`az account show` or `Get-AzContext`) matches the scope agreed with the client.
  3. Run a read-only recon function first, such as `Invoke-EnumerateAzureSubDomains`, before touching anything with write access.
  4. Move to authenticated credential-extraction functions like the Automation account ones only once access is confirmed in scope.
  5. Log every function run and its target resource for the assessment report.
Import-Module — bash
Import-Module .\MicroBurst.psm1; Invoke-EnumerateAzureSubDomains -Base TargetCompany

BEFORE YOU RUN IT

What to check before running it

Functions that pull Automation account or App Service secrets access real credentials — only run them against resources explicitly in scope, and handle anything extracted as sensitive client data.

Azure Automation and App Service reads are recorded in Azure Activity Log and, for AAD auth, Entra ID sign-in logs — agree on expected activity with the client beforehand.

The repository is a script collection, not a single audited binary — read a function's source before running it against production infrastructure.

KEEP EXPLORING

View the whole phase →