Rapid7

module

Azure CLI Credentials Gatherer

Disclosed
N/A

Description

This module will collect the Azure CLI 2.0+ (az cli) settings files
for all users on a given target. These configuration files contain
JWT tokens used to authenticate users and other subscription information.
Once tokens are stolen from one host, they can be used to impersonate
the user from a different host.
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.