Beginner Friendly
![]()
Emulate Storm-0501 Tactics for Cloud Compromise
Storm-0501 is known for hybrid cloud intrusions that end in extortion. Emulate their tradecraft, from password spraying and managed identity abuse to Microsoft 365 data exfiltration.
Overview
Storm-0501 is known for hybrid cloud intrusions that end in extortion. In this lab you will emulate their tradecraft, from password spraying and managed identity abuse to Microsoft 365 data exfiltration.
Scenario
You are on a red team engagement against Mega Big Tech. Emulating the tactics of Storm-0501, show how a foothold in Entra ID can be turned into cloud-wide compromise and data theft.
Lab prerequisites
- Familiarity with the Windows and Linux command line
- Familiarity with Azure and Microsoft 365
Learning outcomes
- Password spray Entra ID accounts
- Exploit command injection and indirect prompt injection
- Abuse an Azure Function App and web app
- Abuse a managed identity to expand access
- Identify and exploit MFA enablement gaps
- Access Azure Blob Storage
- Exfiltrate data out-of-band from Microsoft 365
Real-world context
Storm-0501 is a financially motivated threat actor tracked by Microsoft for hybrid cloud attacks that culminate in data theft and extortion. Emulating real adversary tradecraft is one of the most effective ways to build detection and response capability.
Cloud Security Training To Protect Your Business
Pwned Labs for Business gives your team access to dedicated business content, including labs and cyber ranges.
We also offer in-person or remote workshops, and our cloud penetration services are helping businesses become more secure!