Certified Azure Purple Teamer
Description
Name of Training: Certified Azure Purple Teamer
Trainer: Hackers Academy
Dates: November 08-10, 2026
Time: 9:00 am - 5:00 pm
Venue: Exhibition World Bahrain
Cost: 1200 BHD
1. Short Summary
Learn exactly what groups like LAPSUS, Star Blizzard, Storm-2373, Storm-0485, Storm-0501 and many others do and how you can lock down your Azure tenant to defend against them.
2. Course Description
Follow along with famous APTs, understand and replicate their TTPs in the live lab, then work hard on fortifying your Azure castle.
Designed for cloud engineers, administrators, architects, penetration testers and defenders, this training gives you a solid understanding of the day-to-day operations and resulting misconfigurations, different attacks path and multiple ways for initial access, persistence and privilege escalation. Followed by how you can enforce, audit, monitor and secure your Azure services.
With a great balance between practice and theory, you will quickly get your hands dirty with Azure services and multiple attack tools and techniques.
With 25 Red Labs and 22 Blue Lab, some of the topics covered will include:
- Setting up for successful defense
- Foundations of Azure security: logs, network security, defender, etc.
- Recon and enumeration
- 5 different ways to compromise identities
- Identity protection and defense
- Finding gaps in Conditional Access
- Full Storage attack chain including persistence, C2 and exfil
- Abusing and securing Automation Accounts
- Network Services to lock down your resources
- Key Vaults pillaging, persistence and defense
- Locking down your secrets
- Azure Container Registries misconfigurations and security
- Abusing VMs for tokens, secrets and shell
- Monitoring and detecting VM abuse
- And a lot more!
3. Course Outline
Day 1
3.1 Introduction & Lab Setup
3.1.1 Introduction to Microsoft Azure and some of the most used services
3.1.2 Important Azure concepts and terminology: tenant, subscription, resource groups, resource, etc.
3.2 Defender Essentials
3.2.1 Control and data planes
3.2.2 Roles (IAM and Entra roles)
3.2.3 Different types of logs in Azure
3.2.4 Where to store logs
- Blue Lab: Create Log Analytics
- Blue Lab: Analyze Entra ID Activity Logs
3.3 Network Security
3.3.1 Virtual networks
3.3.2 VNet Service Endpoints
- Blue Lab (optional): Create a VNet & Service Endpoint
3.3.3 Private Endpoints
3.4 Recon
3.4.1 Tenant availability and gather tenant information
- Red Lab: Validating tenant availability
3.4.2 Azure subdomains recon as outsider
3.4.3 Identifying Azure services in use
- Red Lab: Enumerating subdomains
3.4.4 User enumeration in Azure
3.4.5 Understanding error codes
- Red Lab: Enumerating usernames
3.5 Identity Attacks for Initial Access
3.5.1 Entra Connect – Case Study: Mercury & Dev
- Red Lab: Retrieving passwords for on-prem and on-cloud users
3.5.2 Obtaining Valid Credentials – Case Study: LAPSUS$
3.5.3 Credential Stuffing – Case Study: Multiple APTs
3.5.4 Password Spraying – Case Study: Multiple APTs
- Red Lab: Password spraying
3.5.5 Consent Phishing – Case Study: Multiple APTs
- Red Lab: Consent grant
3.5.6 Device Code Phishing – Case Study: Storm-2373
3.5.7 Adversary-in-The-Middle – Case Study: Star Blizzard, Storm-0485
- Red Lab: AiTM
3.5.8 NEW: Device join phishing
3.5.9 NEW: Teams phishing – Case Study: Storm-1674
- Red Lab: Teams calls phishing
3.5.10 NEW: Using AI for phishing lures
3.6 Identity Attacks Defense & Detection
3.6.1 Password spraying
- Defenses, playbooks, triggers and investigation
- Blue Lab: Investigate password spraying
- Blue Lab: Investigate password spraying with IP rotation
3.6.2 Consent Phishing
- Defenses, playbooks, triggers and investigations
- Auditing app permissions
- Understanding consent types
- Blue Lab: Investigate app consent
- Blue Lab: Create and review app consent workbook
3.6.3 AiTM
- Defense best practices
- Understanding different types of tokens
3.6.4 Device Code Phishing
- Best practices for protection
- Conditional Access Policies
- Investigating device code phishing
3.6.5 General Identity Security
- Secure Score for Identity
- Secure Score top actions (password protection, SSPR, MFA, CAPs, PIM etc.)
Day 2
3.7 Conditional Access Policies
3.7.1 Understanding CAPs
3.7.2 What CAPs can and cannot do – Case Study: APT29
3.7.3 Understanding CAP gaps
3.7.4 CAP bypass strategies: membership, location, device, application …
- Red Lab: Bypass CAP
3.7.5 Token types and FOCI
3.7.6 Bypassing CAP with stolen tokens
3.8 Conditional Access Policies – Closing The Gaps
3.8.1 Recommendations and best practices when planning CAPs
3.8.2 What-if tool
3.8.3 Analyzing insights and reporting and understanding CAP impacts
3.8.4 Using Microsoft templates
3.8.5 Gap Analyzer
- Blue Lab: CAP insights and reporting
- Blue Lab: CAP Gap Analyzer
3.9 Entra ID Roles & External Collaboration
3.9.1 Entra ID resources
3.9.2 Deep dive in Azure Entra ID roles and permissions
3.9.3 Understanding users, groups and service principals
3.9.4 Dynamic group membership
3.9.5 Guest invites
- Red Lab: Abusing guest access for persistence
- Red Lab: Abusing dynamic groups for privilege escalation
3.10 External Collaboration Security Strategies
3.10.1 Entra ID risky default settings & their implications
3.10.2 Entitlement Management
3.10.3 Access Packages
- Blue Lab: External Collaboration Identity Governance
3.11 Entra ID App Registrations
3.11.1 Understanding app registration
3.11.2 What are service principals?
3.11.3 Entra ID risky default settings & their implications
3.11.4 App secrets and certificates
3.11.5 Case Study: Nobelium APT
- Red Lab: App registrations for persistence and privilege escalation
3.12 Entra ID App Registrations Security Strategies
3.12.1 Understanding app API permissions
3.12.2 Delegated vs. App permissions
3.12.3 Best practices when using service principals
3.12.4 Reviewing service principal permission assignments
3.12.5 Investigating service principal logins
- Blue Lab: investigate service principal logins
3.12.6 PIM notifications on permissions changes
- Blue Lab: review SP role assignment changes
3.13 Managed Identities
3.13.1 Understanding managed IDs
3.13.2 Where can managed ID be used
3.13.3 Types of managed IDs
3.13.4 Managed ID tokens
3.13.5 IMDS with virtual machines
- Red Lab: Retrieving managed ID token from IMDS
3.14 Managed Identities Security Strategies
3.14.1 Finding and reviewing managed IDs: portal vs. PowerShell vs. Graph Explorer
3.14.2 Reviewing role assignments
3.15 Azure IAM (RBAC)
3.15.1 IAM vs. Entra roles
3.15.2 Primary resource roles
3.15.3 Separation of IAM and Entra roles
3.15.4 Global admin elevation to RBAC – Case Study: Dev-1084 APT
3.16 Storage Attack Chain
3.16.1 Storage types
3.16.2 Storage accounts
3.16.3 Storage endpoints
3.16.4 Storage Access Levels
- Red Lab: Enumerate and access public storage
- Red Lab: Storage enumeration with custom wordlist
3.16.5 3 Types of Shared Access Signatures
3.16.6 Accessing storage with Entra ID credentials
- Red Lab: Storage access with credentials
3.16.7 Storage Account Access – Case Study: Storm-0501
- SAS
- Entra ID authorization
- Shared Keys
- Red Lab: Access account with shared key
3.16.8 NEW: Storage Attack Chain – Case Study: Multiple APTs
- Recon
- Resource development: Storage for phishing infrastructure
- Initial access
- Persistence: IAM manipulation, SAS generation
- Defense Evasion: log tampering and deletion
- Credential Access: token and key extraction, cloud shell
- Discovery: querying for valuable information
- Lateral Movement: targeting functions or automation that uses storage
- Collection: copying and moving data to storage, pre-exfil
- Exfiltration: exfil using web containers, automation accounts, etc.
- C2 using blob storage
- Impact: mass deletion, overwriting or encryption
- Red Lab: Lateral movement using automation accounts and storage
Day 3
3.17 Storage Security
3.17.1 Disabling anonymous access – planning phase
3.17.2 D.R.A.G before disabling anonymous access
- Blue Lab: Investigate storage logs
3.17.3 SAS tracking challenges
3.17.4 SAS best practices: disallow, least privilege, revocation plan
3.17.5 SAS policies
- Blue Lab: Find accounts with SAS
3.17.6 Network security: firewall, private endpoint, secure transfer
3.17.7 Logging & monitoring
- Blue Lab: Monitor for storage authorization
- Blue Lab: Storage Diagnostic Settings
3.18 Automation Accounts PrivEsc and Persistence
3.18.1 Understanding Automation Accounts
3.18.2 Run As vs. Managed Identity
3.18.3 Finding secrets in variables
3.18.4 Runbooks and runbooks’ modules
- Red Lab: Abusing runbook for privilege escalation
- NEW Red Lab: Abusing runbook for reverse shell
3.18.5 Webhooks
- Red Lab: Creating webhook for persistence
3.19 Automation Accounts Security
3.19.1 Job output precautions
3.19.2 Precautions with variables
3.19.3 Using service/private endpoints
3.19.4 Using managed IDs
- NEW Blue Lab: Encrypted variables in Automation Accounts
3.20 Virtual Machines
3.20.1 VM extensions
3.20.2 VM disk snapshots Encrypted vs. Unencrypted
3.20.3 VM run command
- Red Lab: Run command for privilege escalation
3.20.4 NEW: NSGs
- Red Lab: Manipulating NSGs to allow remote access
3.20.5 NEW: Quota manipulation for attack infrastructure – Case Study: Unknown APT
3.21 Virtual Machines Security Strategies
3.21.1 NSG vs. Firewall vs. WAF
3.21.2 Restricting management ports
3.21.3 Understanding Bastion Hosts
3.21.4 PIM access
3.21.5 Azure Update Manager
3.21.6 Disk encryption
- Blue Lab: Retrieving hashes from snapshots – encrypted vs. unencrypted
3.21.7 NEW: Quota alerts expected and unexpected quota consumption
3.22 Key Vaults
3.22.1 Understanding key vaults
3.22.2 Key vault access policies
3.22.3 Key vault IAM
3.22.4 Managed IDs and Key Vaults
- Red Lab: Retrieving secrets from key vaults
3.22.5 Key vault tampering for persistence – Case Study: Unknown APT
3.23 Key Vaults Security Strategies
3.23.1 Key vault RBAC vs. Access Policies
- Blue Lab: Different built-in roles for different jobs
3.23.2 Firewalling key vaults
- Blue Lab: Firewall your key vault
3.23.3 Key vaults on private endpoints
3.23.4 CAPs for key vaults
3.23.5 Purge protection
3.23.6 Monitoring key vaults
- Who’s listing and retrieving secrets
- Who’s accessing the key vaults
- Blue Lab: Queries to monitor retrieving secrets and accessing key vaults
3.24 Azure Container Registries (ACRs)
3.24.1 Container lifecycle
3.24.2 ACR anonymous access
3.24.3 ACR reader access
3.24.4 ACR admin access
- Red Lab: Pulling and inspecting images for secrets
3.25 ACR Security Strategies
3.25.1 ACR authentication best practices
3.25.2 Securing ACR pull
3.25.3 Service endpoints for ACR
3.25.4 Container image vulnerability management
- NEW Blue Lab: Restricting network access to ACRs
3.26 Final Exam
- A CTF style mimicking parts of a breach by Storm-0501.
4. Difficulty Level
Beginner - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.
Intermediate - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.
5. Suggested Prerequisites
Students are not expected to have knowledge of cloud services. However, it would help to have a basic level understanding of cyber security concepts, networking and operating systems.
6. What Students Should Bring
- Students should bring a laptop with RDP client.
- All labs are cloud based.
7. What the Trainer Will Provide
- Students will be provided with all course material. This includes over 300 slides and over 70 pages of lab manuals.
- Cloud labs will be available for each student for 90 hours usage (within 15 days from the start of the training).
- The instructors will share their own lab guides and scripts so students can replicate the setup in their private labs.
8. Trainer Bio
Tim Katsapas
Tim Katsapas is the Founder of Turing Cyber and a senior trainer at Hackers Academy. He is a seasoned security professional with deep expertise in Azure, M365, and hybrid cloud security.
With a strong background in both cloud and on-premises environments, Tim previously worked at Microsoft as a Premier Field Engineer and Cloud Solution Architect specializing in identity and security. His focus included Active Directory and Entra ID security assessments, helping enterprises maximize the value of Entra ID P2 and Microsoft 365 E5 security features.
An MCT since 2008, Tim has delivered technical training globally, including at Microsoft and Black Hat Europe and US. He holds numerous certifications, including OSCP and over 30 Microsoft credentials.
9. Registration Terms and Conditions
9.1 Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.
9.2 Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.
9.3 All trainings are non-refundable after October 21, 2026.
9.4 Training tickets may be transferred to another student. Please email us at training@defcon.org for specifics.
9.5 If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).
9.6 Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.
9.7 DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.
9.8 By purchasing this ticket you agree to abide by the DEF CON Training Code of Conduct and the registration terms and conditions listed above.