Pentest Azure focado em Entra ID (ex-Azure AD), RBAC, Conditional Access, Storage Account público, AKS, Functions e Logic Apps.
Why now
Azure tem 60% do mercado brasileiro de empresa que já tinha Office 365 e migrou infra. Entra ID é o alvo nº1 — phishing, illicit consent grant, app registration backdoor. Pentest Azure manual mira em Entra ID + identity protection + Conditional Access bypass.
Applicable frameworks
/attack-surface
Every engagement is designed for your environment. The points below are part of our standard playbook for this sector — final scope is adapted to your stack and contract.
Sync issues, hybrid identity, illicit consent, app registration, OAuth abuse, password spray, MFA bypass.
Role assignments, Privileged Identity Management, custom roles, escalação via Owner contributors.
Bypass de policy, gaps de plataforma, named locations, device compliance.
Acesso público, shared key, SAS token eterno, immutable storage policy.
RBAC, Azure AD integration, pod identity, network policy, container escape.
Managed identity, function key exposto, Logic App workflow com endpoint público.
/methodology
Automated scanners find what's documented. Real attackers find what isn't. 90% of the work is manual — performed by specialists holding OSCP, CISSP, CRTO and GPEN.
Target mapping, OSINT, footprint, sector-specific threat modeling.
Deep enumeration, complementary scanning, manual exposure identification.
Manual validation with controlled PoC, finding chaining, escalation.
Executive + technical, step-by-step replication, mapped to applicable regulation.
/why-trust
Tenant Azure de organizações com hybrid identity (AD on-prem + Entra) e Office 365 corporativo.
Technical assessment recognized in highly regulated, mission-critical environments — the pentest that finds what nobody had found before.
Douglas Lopes
Founder · CEO · intrus.io
/faq
Sim. BloodHound + AzureHound + ROADtools + MicroBurst pra enumeração de Entra ID e escalação. Tudo manual revisado.
Tenant pequeno: R$ 12-30k. Tenant médio com hybrid: R$ 35-80k. Enterprise multi-tenant: R$ 80-200k.
/contact
Schedule a confidential meeting. Within 48h we'll send a proposal with scope, timeline and pricing.