SpecterOps / SpecterOps/AzureHound
Requesting ability to capture all resources, even those which aren't fully understood by AzureHound
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 961
- Forks
- 148
- Avg merge
- 22h 26m
- Merged PRs (30d)
- 4
Description
AzureHound doesn't support every sort of resource that can exist on Azure, obviously this is a necessary compromise due to the sheer number of resource types. However, even for those resources which don't have explicit support, it would be great if they could still be captured by AzureHound and stored as nodes, so they can be used as targets.
For example, if I have an Azure Database which is considered a high value target, there is no way to evaluate its security using AzureHound, as it does not yet support Azure Databases. If there were an option to capture it as an "unknown" resource, it could still at least be set as a target, and I can see who can get ownership of it.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names no files, tests, or entry points, so first map AzureHound's Azure resource collection and node-modeling paths. Define how unsupported resources become identifiable unknown nodes, then verify that they can be stored, selected as targets, and used to inspect ownership relationships.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, go
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 28/100