Karim El-Melhaoui @karimscloud.bsky.social · 04/05/2025I find it hard to believe that AWS charges me for having hourly data of costs in my AWS environment. 001
Karim El-Melhaoui @karimscloud.bsky.social · 03/05/2025If you were to remove any of the users previously, it had to be done through the REST API, as the permission is inherited on the Tenant Root Group visible in the portal 100
Karim El-Melhaoui @karimscloud.bsky.social · 03/05/2025You can now see users that have triggered the Elevated Access toggle in Azure. A simple bypass is to immediately assign the principal the same permissions at the top level management group, Tenant Root Group (tenant ID) rather than the Root scope ("/"). I still think this is an important feature. 110
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024.. enumerating the sub-domains using subfinder. Following the sub-domain enumeration, the endpoints were further enumerated using GoBuster. GoBuster revealed a Java Spring application with the Actuator endpoint enabled. The Actuator endpoint revealed an AWS Access Key and Heapdumps.. 130