1.4.0 - Compute-control chain added
Compute-control chain added
v1.4.0 is a big step for AzureFox because it closes the gap between flat reconnaissance and defended operator follow-on. This release ships the new compute-control chain family plus first-class container-apps and container-instances commands, so container-heavy environments are now visible both as direct inventory and as joined control-path opportunities. In practice, that means AzureFox can do more of the "what can I reach from here, and why does it matter?" work in one pass instead of making the operator stitch it together manually.
priority when reach from here compute foothold token path identity Azure access proof status
high act now public exposure visible; app-empty-mi service token request app-empty-mi-system Contributor across subscription-wide confirmed
exploitation not proved scope
note
AppService 'app-empty-mi' can request tokens as app-empty-mi-system; that identity already maps to Contributor across subscription-wide scope. To turn this into downstream Azure access, an operator would need server-side execution in this public-facing service. AzureFox is a recon tool and does not verify exploitation activity beyond what is explicitly stated here.
What's Changed
- docs: sharpen positioning and retire planning notes by @TacoRocket in #84
- test: cover vms and snapshots flows by @TacoRocket in #85
- deps: update pytest-cov requirement from <6,>=5.0 to >=5.0,<8 by @dependabot[bot] in #66
- tighten credential-path proof boundaries by @TacoRocket in #86
- Harden deployment-path actionability by @TacoRocket in #87
- deps: update azure-mgmt-network requirement from <27,>=26.0 to >=26.0,<31 by @dependabot[bot] in #35
- fix: harden deployment path joins and docs by @TacoRocket in #88
- Align chain wording and issue scope contract by @TacoRocket in #89
- deps: update azure-mgmt-resource requirement from <24,>=23.1 to >=23.1,<26 by @dependabot[bot] in #33
- Tighten chain-family output wording and proof boundaries by @TacoRocket in #90
- Finish deployment-path slice by @TacoRocket in #91
- Refine compute-control mixed identity paths by @TacoRocket in #93
- Add container workload coverage and tighten compute-control by @TacoRocket in #94
- Refine chains README blurbs by @TacoRocket in #95
- chore: prepare v1.4.0 release by @TacoRocket in #96
Full Changelog: v1.3.0...v1.4.0