SpecterOps / SpecterOps/AzureHound

Requesting ability to capture all resources, even those which aren't fully understood by AzureHound

Open
#41 1 comment 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
961
Forks
148
Avg merge
22h 26m
Merged PRs (30d)
4

Description

AzureHound doesn't support every sort of resource that can exist on Azure, obviously this is a necessary compromise due to the sheer number of resource types. However, even for those resources which don't have explicit support, it would be great if they could still be captured by AzureHound and stored as nodes, so they can be used as targets.

For example, if I have an Azure Database which is considered a high value target, there is no way to evaluate its security using AzureHound, as it does not yet support Azure Databases. If there were an option to capture it as an "unknown" resource, it could still at least be set as a target, and I can see who can get ownership of it.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue names no files, tests, or entry points, so first map AzureHound's Azure resource collection and node-modeling paths. Define how unsupported resources become identifiable unknown nodes, then verify that they can be stored, selected as targets, and used to inspect ownership relationships.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, go
Domain
cloud, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
28/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.