MicroBurst Azure

Import-Module MicroBurst.psm1; Get-AzurePasswords

Enumerate resources and extract Azure credentials (VM users, service accounts) using NetSPI's MicroBurst suite.

Run this when you have credentials for an Azure account and want to map the tenant and subscriptions. Get-AzurePasswords reviews VMs and extracts local credentials from access extensions (VMAccessAgent) and stored service accounts: it's the most cost-effective module in the kit.

Every Azure API (ARM) call is logged in the Activity Log with your principal. MicroBurst is flagged by CASB and Defender as an offensive tool. If the account has Conditional Access or PIM, it may not reach subscriptions.