This is our 2-day Advanced-level infrastructure hacking course.
Designed for cloud red teamers and security professionals, this intensive course targets the rapidly expanding attack surface within Microsoft Azure—where identity, infrastructure, automation, and AI workloads converge. As organizations shift critical services to the cloud, Azure has become a prime focus for adversaries.
2 day practical class
Available by Partners
Live, online available
Hack-Lab for 30 days
Intermediate
Course Overview
For 2 intensive days, you will step directly into the attacker mindset and execute a full kill chain across Microsoft Azure using our state-of-the-art cloud hacklabs. You’ll exploit real misconfigurations, abuse identity flaws, escalate privileges across Azure Resource Manager and DevOps services, bypass Conditional Access, and use AI-assisted enumeration workflows to uncover attack paths that mirror real adversaries.
By the end of the course, you’ll be fully equipped to compromise, analyse, and secure Azure environments with confidence — including those hosting modern AI workloads.
Note: This 2-day course is a high-intensity version of our extended cloud exploitation program.
You will work across attack surfaces such as:
- Azure Resource Manager (App Services, Function Apps, Logic Apps, Key Vault, Automation)
- Azure DevOps pipelines, service connections, repos, and container registries
- Microsoft Entra ID: MFA bypass, CA policy evasion, dynamic group abuse
- Azure Storage misconfigurations
- Cloud-to-on-prem pivoting scenarios
- Hybrid cloud abuse via Azure Arc
- AI-assisted cloud enumeration using tools like Graphunter
- Persistence and backdooring techniques across Azure services
- Cloud logging, detection, and visibility gaps
Note: Students will gain access to a dedicated Azure attack lab environment with real misconfigurations and exploitation paths, plus 1 month of extended lab access after the class for additional practice.

Interested?
1. Our courses are available directly from us; through our training partners or at worldwide technical conferences.
2. You can find course dates and prices on the Courses and Webinars page.
3. Take a look below at a few of the upcoming courses for this specific training.
4. For more information including private course requests, complete the short form below.
Courses and webinars
Booking enquiries
Select the course from the Courses and Webinars Page.
Click here for course dates and prices
For private course delivery enquiries or other information, please use the form alongside.
The course is also available from our partners listed below.
For security and IT decision makers
What’s the real impact of training your team through NotSoSecure?
Harden your organisation’s infrastructure and make it a less attractive target for attackers by building a team that can identify, test, and recommend remediations for vulnerabilities and misconfigurations throughout your environments. Trained delegates can:
- Perform security testing that uses complex attack chaining across Windows (local), Active Directory, Linux, and common cloud environments.
- Design this testing around real-world attacker behaviour and tooling to ensure its relevance to the threats facing your organisation.
- Identify misconfigurations from network level to system level.
- Understand the business impact of misconfigurations and vulnerabilities and articulate this to key stakeholders.
- Implement logging and monitoring processes to detect live attacks.
- Take on greater responsibility in the team and become an advocate of security in the wider business.
Course Details
Who is it for?
This course is designed for professionals responsible for assessing, defending, or architecting Microsoft Azure environments, including:
- Cloud administrators and architects
- Penetration testers and red teamers
- CSIRT/SOC analysts and engineers/blue teams
- Developers
- Security/IT managers and team leads
- Basic to intermediate knowledge of cybersecurity (1.5+ years’ experience)
- Familiarity with command-line tooling, including Azure CLI
- Execute full kill-chain exploitation across Azure services, chaining weaknesses in Azure Resource Manager, Azure DevOps, and identity layers to demonstrate realistic privilegeescalation paths and understand how attackers traverse interconnected cloud workloads.
- Master high-fidelity enumeration techniques, including the use of AI-assisted tooling (such as our Graphunter-based workflows), to rapidly uncover misconfigurations, insecure identities, and exposed assets within Azure environments.
- Deeply understand Microsoft Entra ID weaknesses, including misconfigured roles, app registrations, and advanced techniques for bypassing Conditional Access Policies to achieve unauthorized access or escalate privileges.
- Adopt the mindset and workflow of a modern threat actor, mapping attacker objectives to Azure-specific tradecraft.
- Identify and exploit advanced misconfigurations across Microsoft Azure, including identity, resource, network, and automation layers.
- Design penetration tests that mirror real adversarial behavior, using attacker-grade tooling, reconnaissance methods, and post-exploitation techniques.
- Understand the attack surface created by core Azure services, including virtual machines, storage accounts, containers/Kubernetes, service principals, serverless functions, and CI/CD pipelines.
- Leverage AI where it truly matters in cloud pentesting, such as accelerating enumeration, analysis, and attack-path discovery through AI-assisted tools and workflows.
- Engaging in lab-driven exercises for ~70% of the course, following attacker workflows end-toend.
- Exploring and compromising lifelike Azure environments, simulating enterprise-grade cloud deployments.
- Executing offensive, defensive, and auditing techniques across identity, compute, storage, and automation services.
- Participating in a Capture the Flag (CTF) challenge to validate your skills under realistic constraints.
- Reviewing case studies based on real-world breaches, understanding the operational impact and defensive lessons from each exploitation path.
- Introduction to the Cloud
- Importance of Cloud Security
- Importance of Cloud Metadata API from an Attacker’s perspective
- Introduction to the Azure
- Importance of DNS in the Cloud
- DNS-based Enumeration
- Open-Source Intelligence Gathering (OSINT) techniques for Cloud Asset Enumeration
- Username enumeration using Cloud provider APIs and Leaked Database
- Introduction to Azure Storage
- Azure: Shared Access Signature (SAS) URL Misconfiguration
- Azure Application Attacks on App Service, Function App and Storages
- Azure Database
- Automation Account
- Hybrid Automation Account Abuse
- Azure Key Vault
- Azure Logic Apps
- Introduction to Azure DevOps
- Understanding Azure DevOps Service Connection and potential abuse.
- Kerberos authentication
- Exploiting Azure repository and Azure container registry for sensitive information.
- Introduction to Microsoft Entra ID authentication methods and associated risks.
- Attacking Microsoft Entra ID, focusing on Managed User Identities
- Bypassing MFA security and evading Conditional Access Policies
- Exploiting Dynamic Membership Policies for privilege escalation
- Leveraging Azure Identity Protection to detect and respond to threats
- Using Refresh Tokens to Maintain Persistent Access to Office 365 and SharePoint Drive
The training is suitable for anyone with a direct stake in Azure security—from hands-on practitioners to decision-makers who need a deeper understanding of cloud attack surfaces. The curriculum blends Azure misconfigurations, identity abuse, and advanced cloud exploitation techniques, enabling attendees to effectively identify, validate, and communicate real security gaps in enterprise cloud environments.
Through a structured, offensive testing methodology and hands-on labs, participants gain practical experience in discovering, exploiting, and interpreting Azure security risks. These skills directly translate to day-to-day penetration testing, red team operations, and defensive validation, including environments hosting AI workloads or exposed APIs.
To ensure participants get maximum value from the course, the following baseline is recommended:
Top 3 Takeaways
What You Will Learn
This course uses a Defence by Offense methodology built on real-world red-team engagements and offensive research—not theory. Every technique demonstrated has been used and validated in live environments and can be immediately applied in real assessments. By the end of the course, you will be able to:
What You Will be Doing
This is a highly hands-on, operator-focused course. You will spend the majority of your time in live labs, practicing real offensive techniques:
Why it is Relevant
The cybersecurity skills shortage is felt perhaps nowhere as deeply as in the cloud. With new rulebooks and standards, practitioners often find themselves playing catch up with the latest developments in technology and in the threat landscape. This course is designed to be a highly informative boot camp to help you advance your skills in the most important and relevant areas of cloud security. Across 2 days, you’ll learn about the high-impact misconfigurations and flaws that could be open in your organization right now and how to fix them.
Our syllabuses are revised regularly to reflect the latest in-the-wild hacks, the newest system releases, and whatever proof of concepts we’ve been developing in our own research. Because they remain so up to date with the threat landscape and security industry standard, many delegates return every 1-2 years to update their skills and get a refresh.
Details of the course content:
Note: Our syllabuses are subject to change based on new vulnerabilities found and exploits released.
INTRODUCTION TO AZURE AND CLOUD COMPUTING
This module introduces the core concepts of cloud computing, emphasizing the importance of security. It explores the shared responsibility model, comparing cloud security with traditional models. Additionally, it sheds light on the significance of cloud metadata APIs from an attacker's perspective. This module lays the groundwork for a deeper understanding of cloud security and its unique challenges.
CLOUD ASSET ENUMERATION FOCUSING AZURE ENVIRONMENT
This module will explore DNS-based Enumeration techniques, gaining insights into identifying cloud assets through DNS records.
The module then delves into "OSINT Techniques for Cloud Asset Enumeration," equipping participants with open-source intelligence methods to uncover valuable information. Additionally, it covers "Username Enumeration using Cloud Provider APIs," and Leaked database empowering attendees to utilize cloud provider APIs to enumerate usernames effectively.
AZURE STORAGES
This module culminates with a focus on securing Azure's Shared Access Signature (SAS) URLs. Attendees will gain the knowledge and skills to secure their cloud storage effectively, avoiding common pitfalls and optimizing data protection in these cloud environments.
ATTACKING MICROSOFT AZURE RESORUCE MANAGER SERVICES
The module extensively covers "Azure Resource Manager Attacks" across critical components such as App Service, Function App, Database, Automation Account, Key Vault and Logic Apps. Techniques for exploiting misconfigurations and escalating privileges across these services are explained in depth.
ATTACKING AZURE DEVOPS
This module provides an in-depth analysis of the security implications of Azure DevOps, focusing on potential privilege escalation scenarios we have reported to Microsoft—content not commonly found in other courses.
Participants will also learn how to enumerate other key DevOps services, such as Azure Repos and Azure Container Registry, which are closely integrated with Azure DevOps for daily operations.
AZURE ARC SERVICE
This module provides an in-depth analysis of the security implications of Azure Arc, focusing on potential privilege escalation scenarios in a hybrid cloud environment.
Participants will learn how Azure Arc integrates with on-premises and multi-cloud environments, enabling the management of resources across different infrastructures.
ABUSING ENTRA ID MISCONFIGURATIONS
This module provides an in-depth analysis of Microsoft Entra ID, focusing on its authentication methods, security risks, and attack scenarios in cloud environments. It covers MFA bypass, Conditional Access policy evasion (using our noprompt tool), enumeration and attack path discovery using Graph tokens and our AI-assisted Graphhunter tool, Dynamic Membership Policy abuse, and persistent access using refresh tokens across Office 365 and SharePoint.
BACKDOORING AZURE ENVIRONMENTS: PERSISTENCE TECHNIQUES
This module explores techniques attackers use to backdoor Azure environments, ensuring persistent access while remaining unnoticed. Participants will learn how to manipulate Azure configurations, exploit identity and access management (IAM) flaws, and abuse legitimate services to maintain unauthorized access. The session also covers defensive measures to detect and mitigate such threats.
Participants will learn how Azure Arc integrates with on-premises and multi-cloud environments, enabling the management of resources across different infrastructures.
AZURE AD IDENTITY PROTECTION
This module provides an in-depth understanding of Azure AD Identity Protection, focusing on its security mechanisms, risk detection, and potential attack vectors. Participants will learn how Microsoft Entra ID analyzes sign-in behavior, detects threats, and enforces security policies.
What You Will Get
- Certificate of completion
- 30 days lab access post-course completion (with the opportunity to extend)
- 8 Continuing Professional Education (CPE) credits awarded per day of training fulfilled
- Learning pack, including Q&A sheets, setup documents, and command cheat sheets
Course Highlights
What Delegates Love:
- Our labs: Probably the biggest selling point for our courses. Not only will you spend most of the course hacking hands-on in a lifelike web environment, but you’ll also have 30+ days of access to practice your new skills afterwards.
- Individual access: You’ll have your own infrastructure to play with, enabling you to hack at your own speed.
- Real-world learning: Where many leading cybersecurity training courses are based on theory, our scenario-led, research-based approach ensures you learn how real threat actors think and act.
- Specialist-led training: You’ll learn from highly skilled and experienced practicing penetration testers and red teamers.
- Up-to-date content: Our syllabus remains so relevant that delegates come back year afteryear.
- Remediations included: You’ll learn how to fix as well as find vulnerabilities.
Outcomes for Budget Holders
This course is designed to bring your in-house cloud security testing competency up to industry standard, helping you to:
- Lower the likelihood of security incidents by identifying weaknesses in your cloud infrastructure.
- Improve your understanding of the organization’s risk posture based on the frequency and severity of weaknesses identified.
- Improve the organization’s approach to access control management.
- Create a stronger case for securing software development, cloud deployment, and governance practices.
- Develop a secure cloud roadmap that balances growth and risk.
- Implement cloud-based attack detection and response tactics.
- Build a closer relationship between development and security teams
- Internally pentest new tools and systems before making an investment.
- Nurture and retain passionate, highly skilled, and security-conscious employees.
- Demonstrate commitment to security through training, compliance, and change management.
- Develop the organization’s competitive advantage for security-conscious customers.
Prerequisites
Who should take this class?
- Penetration testers and red teamers
- CSIRT/SOC analysts and engineers/blue teams
- Developers
- Security/IT managers and team leads
What you will learn:
This course is suitable for anyone with a stake or interest in Azure cloud security, from technical practitioners to decision-makers. The syllabus is designed to cover Azure cloud misconfigurations and advanced hacking techniques while equipping participants with the skills to conduct penetration tests on cloud environments and identify security gaps effectively.
Additionally, this course provides a practical, hands-on approach to cloud penetration testing, allowing participants to apply the acquired skills directly in their day-to-day pen-testing activities. By following a structured pen-testing methodology, attendees will gain real-world experience in assessing, exploiting, and understanding Azure security risks.
For decision makers:
This course is designed to bring your in-house cloud security testing competency up to industry standard, helping you to:
- Lower the likelihood of security incidents by identifying weaknesses in your cloud infrastructure.
- Improve your understanding of the organization’s risk posture based on the frequency and severity of weaknesses identified.
- Improve the organization’s approach to access control management.
- Create a stronger case for securing software development, cloud deployment, and governance practices.
- Develop a secure cloud roadmap that balances growth and risk.
- Implement cloud-based attack detection and response tactics.
- Build a closer relationship between development and security teams.
- Internally pentest new tools and systems before making an investment.
- Nurture and retain passionate, highly skilled, and security-conscious employees.
- Demonstrate commitment to security through training, compliance, and change management.
- Develop the organization’s competitive advantage for security-conscious customers.

Course Information
You can download a copy of the course information below.
In addition you will also be provided with a student pack, handouts and cheat-sheets if appropriate.
Your Training Roadmap
Offensive Classes
Hacking training for all levels: new to advanced. Ideal for those preparing for certifications such as CREST CCT (ICE), CREST CCT (ACE), CHECK (CTL), TIGER SST as well as infrastructure / web application penetration testers wishing to add to their existing skill set.
Defensive Classes
Giving you the skills needed to get ahead and secure your business by design. We specialise in application security (both secure coding and building security testing into your software development lifecycle) and cloud security. Build security capability into your teams enabling you to move fast and stay secure.

