<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Redteam on Daniyal Ahmed | Red Team &amp; Cloud Security</title><link>https://daniyalahmed.dev/tags/redteam/</link><description>Recent content in Redteam on Daniyal Ahmed | Red Team &amp; Cloud Security</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><managingEditor>daniyal.ahmed@microtechx.com (Daniyal Ahmed)</managingEditor><webMaster>daniyal.ahmed@microtechx.com (Daniyal Ahmed)</webMaster><lastBuildDate>Sun, 26 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://daniyalahmed.dev/tags/redteam/index.xml" rel="self" type="application/rss+xml"/><item><title>Serverless Security: Auditing Local Cache Storage and Runbook Permissions in Azure</title><link>https://daniyalahmed.dev/posts/serverless-security-auditing-local-cache-storage-and-runbook-permissions-in-azure/</link><pubDate>Sun, 26 Jul 2026 00:00:00 +0000</pubDate><author>daniyal.ahmed@microtechx.com (Daniyal Ahmed)</author><guid>https://daniyalahmed.dev/posts/serverless-security-auditing-local-cache-storage-and-runbook-permissions-in-azure/</guid><description>When hardening an enterprise cloud environment, security teams often spend their time auditing internet facing virtual machines or locking down administrative user accounts. However, a less discussed but incredibly high value risk vector exists within serverless orchestration engines: Azure Automation Accounts.
During a recent environment configuration review, we mapped an execution pipeline that demonstrates exactly how an oversight in local workspace hygiene combined with over-privileged service roles can expose an entire tenant subscription.</description></item></channel></rss>