Skip to content

azrte-TheToddLuci0#310

Merged
carlospolop merged 1 commit into
HackTricks-wiki:masterfrom
TheToddLuci0:azure_alert_phishing
Jun 21, 2026
Merged

azrte-TheToddLuci0#310
carlospolop merged 1 commit into
HackTricks-wiki:masterfrom
TheToddLuci0:azure_alert_phishing

Conversation

@TheToddLuci0

Copy link
Copy Markdown
Contributor

Details on how to use Azure Monitor to send fully validated emails from azure-noreply@microsoft.com. The notable element here is the ability to bypass the email that is typically sent to a user when they are added to an alert group, potentially allowing an attacker to trick a privileged user into thinking it's a legitimate communication.

This was disclosed to Microsoft on March 17th, 2026. They assigned it a moderate severity and closed the issue.

@carlospolop carlospolop merged commit db20d27 into HackTricks-wiki:master Jun 21, 2026
@carlospolop

Copy link
Copy Markdown
Collaborator

thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants