Skip to main content
Storm-2949: Azure VM Run Command, VMAccess Backdoor, and Key Vault Secret Dump operation cover
COMING SOONAdvancedPRO

Storm-2949: Azure VM Run Command, VMAccess Backdoor, and Key Vault Secret Dump

A hands-on-keyboard intrusion that turned one compromised cloud identity into control over an entire Azure estate. After seizing a finance user's account through self-service password reset abuse and attacker-owned MFA, the operator enumerated the tenant, escalated with an RBAC role assignment, harvested App Service publishing profiles, rewrote a Key Vault access policy and dumped every secret in four minutes, stole storage keys, and finished on a production VM using the VMAccess extension to mint a backdoor admin and Run Command to disable Defender and install ScreenConnect. Reconstruct the kill chain from the Azure cloud audit trail and the VM's endpoint XDR telemetry, and classify the key ATT&CK techniques.

1h 25m
9 tasks
150 points
Pro

Launches in 2 days

Sep 22, 2026

Tuesday, September 22, 2026 at 9:00 AM

View Pro plans

Pro unlocks this operation at launch.

Training Tools

CloudXDRQuery

What you'll investigate

9 objectives unlock when this operation goes live.

1Incident brief
2Identify the compromised identity
3Classify the persistence on the identity
4Find the secret store that was emptied
5Classify the secret-dump technique
6Recover the backdoor administrator
7Classify the on-VM execution method
8Recover the RMM persistence indicator
9Isolate the RMM relay

Be first when it launches

Create your account and grab Pro before launch. The moment this operation goes live on Sep 22, 2026, you can jump straight in.

Get Started Free