Rabat, MoroccoOn-site · Virtual classroom · Corporate training
contact@avnorysacademy.com

Offensive cybersecurity

Microsoft Azure offensive security

Assess attack paths involving identities, Azure resources and cloud configurations in an authorised lab.

Learning objectives

  • Model the Azure and Entra attack surface
  • Identify IAM weaknesses and exposed resources
  • Analyse privilege and persistence paths
  • Communicate risks and prioritise cloud remediation

Who should attend

Cloud penetration testers, Azure security engineers, architects and red teamers.

Prerequisites

Experience with Azure, Microsoft Entra, networking, PowerShell or Azure CLI, and offensive security.

Course outline

  • Responsibility model, rules of engagement and Azure architecture
  • Reconnaissance of tenants, identities, applications and workloads
  • RBAC, Entra roles, consent, secrets and managed identities
  • Storage, compute, networking, Key Vault and application services
  • Cloud attack paths, persistence and logging
  • MITRE Cloud mapping, evidence and executive reporting

Learning approach

Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.

Reference source: MITRE ATT&CK Enterprise, matrice Cloud ↗
Programme restricted to authorised environments. This is an independent Avnorys programme with no affiliation with Microsoft or MITRE.