{"id":8081,"date":"2025-10-31T10:03:27","date_gmt":"2025-10-31T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/31\/azurehound-penetration-testing-tool-weaponized-by-threat-actors-to-enumerate-azure-and-entra-id\/"},"modified":"2025-10-31T10:03:27","modified_gmt":"2025-10-31T10:03:27","slug":"azurehound-penetration-testing-tool-weaponized-by-threat-actors-to-enumerate-azure-and-entra-id","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/31\/azurehound-penetration-testing-tool-weaponized-by-threat-actors-to-enumerate-azure-and-entra-id\/","title":{"rendered":"AzureHound Penetration Testing Tool Weaponized by Threat Actors to Enumerate Azure and Entra ID"},"content":{"rendered":"<p>    AzureHound Penetration Testing Tool Weaponized by Threat Actors to Enumerate Azure and Entra ID<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>AzureHound, an open-source data collection tool designed for legitimate penetration testing and security research, has become a favored weapon in the hands of sophisticated threat actors.<\/p>\n<p>The tool, which is part of the BloodHound suite, was originally created to help security professionals and red teams identify and fix <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-thinkphp-owncloud-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">cloud vulnerabilities<\/a>.<\/p>\n<p>However, malicious actors have increasingly misused this capability to map out Azure environments and discover pathways for privilege escalation attacks.\u200b<\/p>\n<p>The tool operates by collecting data through Microsoft Graph and Azure REST Application Programming Interfaces (APIs), allowing it to enumerate Entra ID and Azure environments to gather information about identities and resources.<\/p>\n<p>Written in the Go programming language and available as precompiled versions for Windows, Linux, and macOS, AzureHound proves particularly dangerous because it does not need to be run from within a <a href=\"https:\/\/cybersecuritynews.com\/xiaomis-interoperability-app-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">victim\u2019s<\/a> network.<\/p>\n<p>Since both APIs are accessible externally, threat actors can launch discovery operations remotely after gaining initial access to compromised systems.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-how-threat-actors-weaponize-the-tool\"><strong>How Threat Actors Weaponize the Tool<\/strong><\/h2>\n<p>When threat actors gain access to a victim\u2019s Azure environment, they deploy AzureHound to automate discovery procedures that would otherwise require extensive manual effort.<\/p>\n<p>The tool helps attackers discover user hierarchies, identify high-value targets, and uncover misconfigurations or indirect <a href=\"https:\/\/cybersecuritynews.com\/windows-cloud-files-minifilter-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">privilege escalation<\/a> opportunities that might otherwise remain hidden.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"242\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-93-1024x242.png?resize=1024%2C242&#038;ssl=1\" alt=\"Execution of AzureHound to enumerate users.\" class=\"wp-image-131894\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-93-1024x242.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-93-300x71.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-93-768x182.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-93-696x165.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-93-1068x253.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-93-150x35.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-93.png 1310w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">Execution of AzureHound to enumerate users<\/figcaption><\/figure>\n<p>By gathering comprehensive internal Azure information, attackers can develop targeted attack strategies with surgical precision.\u200b The tool outputs data in JSON format, which can be ingested by BloodHound\u2019s visualization capabilities.<\/p>\n<p>This creates a graphical representation of hidden relationships and attack paths within the target\u2019s infrastructure, giving attackers a complete roadmap of the environment they have infiltrated.<\/p>\n<p>This combination of automated discovery and visual analysis transforms cloud reconnaissance from a time-consuming process into an efficient operation. Recent threat intelligence reveals the widespread adoption of AzureHound across multiple adversary groups.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"470\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-94-1024x470.png?resize=1024%2C470&#038;ssl=1\" alt=\"BloodHound illustration of available key vaults.\" class=\"wp-image-131896\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-94-1024x470.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-94-300x138.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-94-768x353.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-94-915x420.png 915w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-94-696x319.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-94-1068x490.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-94-150x69.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-94.png 1525w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">BloodHound illustration of available key vaults<\/figcaption><\/figure>\n<p>Unit 42 <a href=\"https:\/\/unit42.paloaltonetworks.com\/threat-actor-misuse-of-azurehound\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">researchers<\/a> have tracked the Iranian-backed group Curious Serpens, also known as Peach Sandstorm and active since at least 2013, leveraging AzureHound to conduct internal discovery operations against target Microsoft Entra ID environments.\u200b<\/p>\n<p>In May 2025, Microsoft disclosed that suspected nation-state threat actor Void Blizzard employed AzureHound during the discovery phase of their campaigns to enumerate Entra ID configurations.<\/p>\n<p>More recently, in August 2025, Microsoft reported Storm-0501, a ransomware operator, using AzureHound to enumerate target Entra ID tenants while operating in hybrid, multi-tenant Azure environments.\u200b<\/p>\n<p>Organizations using Azure and <a href=\"https:\/\/cybersecuritynews.com\/microsoft-entra-id-extend-passkey-fido2\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Entra ID<\/a> must recognize that tools like AzureHound leave detectable evidence when used maliciously.<\/p>\n<p>Security teams should focus on detecting abnormal API activity, monitoring for suspicious enumeration patterns, and implementing strong identity and access controls.<\/p>\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"826\" height=\"197\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-95.png?resize=826%2C197&#038;ssl=1\" alt=\"AzureHound API test requests\" class=\"wp-image-131897\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-95.png 826w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-95-300x72.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-95-768x183.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-95-696x166.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2025\/10\/image-95-150x36.png 150w\" sizes=\"(max-width: 826px) 100vw, 826px\"><figcaption class=\"wp-element-caption\">AzureHound API test requests<\/figcaption><\/figure>\n<p>Understanding how threat actors misuse legitimate tools is essential for building effective detection capabilities and responding quickly to compromise indicators in <a href=\"https:\/\/cybersecuritynews.com\/cloud-misconfigurations\/\" target=\"_blank\" rel=\"noreferrer noopener\">cloud environments<\/a>.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/azurehound-enumerate-azure-entra-id\/\">AzureHound Penetration Testing Tool Weaponized by Threat Actors to Enumerate Azure and Entra ID<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/azurehound-enumerate-azure-entra-id\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AzureHound Penetration Testing Tool Weaponized by Threat Actors to Enumerate Azure and Entra ID AzureHound, an open-source data collection tool designed for legitimate penetration testing and security research, has become a favored weapon in the hands of sophisticated threat actors. The tool, which is part of the BloodHound suite, was originally created to help security [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[147,129,63,1465],"tags":[130],"class_list":["post-8081","post","type-post","status-publish","format-standard","hentry","category-azure","category-cyber-security","category-cyber-security-news","category-threat-actors","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8081"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8081"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8081\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}