Uploaded August 2025 | Updated September 2026, 1 hour ago
Tung-Lin Lee (Cycraft, TW)
Tung-lin Lee is a cybersecurity researcher at CyCraft Technology, specializing in network and cloud security. He has presented at several industry conferences, including HITCON ENT, ROOTCON, InfoSec Taiwan, and CyberSec.
--
In our journey of developing an attack path analysis tool for Azure, we encountered several obstacles, primarily derived from outdated and unclear documentation of Entra APIs which is partially mitigated by the amazing open-source project Bark. However, the issue was further compounded by API permission misalignments across different APIs, such as the Provisioning API and Azure AD Graph API.In addition, the rising prevalence of research into undocumented APIs reveals a neglected attack surface. Moreover, we discovered that the token redemption mechanisms behind the Azure Portal present additional attack vectors. By manipulating the mechanisms, threat actors would abuse multiple undocumented APIs & expand Microsoft Graph permission scopes after obtaining a single refresh token.To address these risks, we are developing an open-source framework for precise identity risk assessments in Azure and laying the groundwork for building safer security solutions.
Tung-Lin Lee (Cycraft, TW)
Tung-lin Lee is a cybersecurity researcher at CyCraft Technology, specializing in network and cloud security. He has presented at several industry conferences, including HITCON ENT, ROOTCON, InfoSec Taiwan, and CyberSec.
--
In our journey of developing an attack path analysis tool for Azure, we encountered several obstacles, primarily derived from outdated and unclear documentation of Entra APIs which is partially mitigated by the amazing open-source project Bark. However, the issue was further compounded by API permission misalignments across different APIs, such as the Provisioning API and Azure AD Graph API.In addition, the rising prevalence of research into undocumented APIs reveals a neglected attack surface. Moreover, we discovered that the token redemption mechanisms behind the Azure Portal present additional attack vectors. By manipulating the mechanisms, threat actors would abuse multiple undocumented APIs & expand Microsoft Graph permission scopes after obtaining a single refresh token.To address these risks, we are developing an open-source framework for precise identity risk assessments in Azure and laying the groundwork for building safer security solutions.







