Master Production-Ready Machine Learning, Step by Step
Stuck in Tutorial Hell? Learn Backend Dev the Right Way
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Explore the security vulnerabilities and attack vectors present in Azure Logic Apps through this 31-minute conference talk from NorthSec 2025. Examine how attackers can exploit misconfigurations in this powerful workflow automation tool to compromise cloud environments, including exposure of sensitive data through improperly secured Logic Apps, execution of malicious inline C# code, privilege escalation within storage accounts, and API connection hijacking. Learn about techniques for cloud-to-on-premises lateral movement and discover the often-overlooked risks of custom authorization logic with real-world examples of bypassed authentication mechanisms leading to unauthorized access and data breaches. Investigate broader security implications including overly permissive role-based access control (RBAC), insecure service principals, and unprotected external system connections that enable privilege escalation and lateral movement across cloud and on-premises environments. Analyze real-world exploitation scenarios and dissect critical workflow vulnerabilities while understanding effective countermeasures to strengthen Logic App security implementations and ensure resilient cloud operations.
Syllabus
NorthSec 2025 - White Knight Labs - Exploring Azure Logic Apps
Taught by
NorthSec