Skip to main content
Key Vault Contributor Privilege Escalation: Reading All Secrets via Access Policies operation cover
COMING SOONIntermediatePRO

Key Vault Contributor Privilege Escalation: Reading All Secrets via Access Policies

A holder of the built-in Key Vault Contributor role abuses its Microsoft.KeyVault/vaults/write permission to write itself a full data-plane access policy on a production Azure Key Vault, then dumps every secret, key, and certificate it holds. Working purely from the cloud audit trail, correlate the control-plane access-policy change in the Azure Activity Log with the data-plane secret, key, and certificate reads in the Key Vault diagnostic log, identify the principal and what it stole, and classify the privilege-escalation and credential-access techniques.

40m
8 tasks
50 points
Pro

Launches in 5 days

Sep 29, 2026

Tuesday, September 29, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

CloudQuery

What you'll investigate

8 objectives unlock when this operation goes live.

1Incident brief
2Identify the principal behind the vault activity
3Pin down the escalation operation
4Classify the privilege-escalation technique
5Inventory the stolen payment credential
6Catch the highest-impact data-plane read
7Locate the operator's source address
8Classify the credential-theft outcome

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Sep 29, 2026, you can jump straight in.

Get Started Free