Skip to content

Security: dx7er/AzureConsentLab

Security

SECURITY.md

Security Policy

Scope

This repository contains a defensive research lab. The attack walkthrough it documents targets an isolated Altered Security training tenant and is published to help defenders detect and prevent the technique in their own environments.

Nothing in this repository should be run against a tenant you do not own or have explicit written authorisation to test. Doing so is unauthorised access under the UK Computer Misuse Act 1990 and equivalent legislation elsewhere.

Reporting a vulnerability in this project

If you find a vulnerability in any code shipped in this repository, please report it privately before opening a public issue.

  • Email: dx73r@protonmail.com with the subject line [SECURITY] AzureConsentLab: <short description>
  • Please include: affected component, reproduction steps, impact assessment, and any suggested fix.
  • I will acknowledge within 72 hours and aim to publish a fix or mitigation within 30 days.

Out of scope

  • Vulnerabilities in Microsoft Entra ID, Microsoft Graph, or Microsoft 365. Report those to the Microsoft Security Response Center.
  • Vulnerabilities in third-party tools referenced by this project (e.g. 365-Stealer). Report those to the respective maintainers.
  • Issues in the copyrighted CARTP course material. That material is not distributed here.

Handling of sensitive material

The _private/ directory is .gitignored and used for personal notes and copyrighted reference material. Do not open pull requests that add files under that path.

There aren't any published security advisories