Contoso-State

62 mods across 1 repository, 6 stars between them.

azure-redteam-ai

01

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to assess Azure AI and machine-learning security during a red team engagement. Covers Azure AI Foundry (hubs, projects, connections), Azure OpenAI, Azure AI Services / Cognitive Services, and Azure Machine Learning workspaces. Finds public network access on AI endpoints, key-based auth instead of…

6 28d ago A 121 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to assess Azure container and Kubernetes security during a red team engagement. Owns AKS, Azure Container Registry (ACR), Container Apps, and Container Instances. Finds public API servers, local-admin kubeconfig, missing Entra/Azure RBAC for Kubernetes, no network policy, Pod Security Admission gaps…

6 28d ago A 181 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to analyze Azure RBAC and map privilege escalation and lateral movement attack paths during an Azure red team engagement. Finds over-permissioned roles, dangerous custom roles, escalation primitives (roleAssignments/write, runCommand, listClusterAdminCredential), managed identity abuse, and correlates…

6 28d ago A 99 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to assess Azure compute security during a red team engagement. Covers VMs, VM Scale Sets, App Service, and Functions. Finds unmanaged disk encryption, exposed managed identities, insecure custom script extensions, runCommand exposure, remote debugging, missing auth, plaintext secrets in app settings…

6 28d ago A 115 tokens original MIT

azure-redteam-data

05

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to assess Azure data protection security during a red team engagement. Covers Storage accounts, Key Vault, SQL/PostgreSQL/MySQL/Cosmos DB. Finds public blob containers, anonymous access, shared-key auth, permissive SQL firewall rules (0.0.0.0 / allow Azure services), missing TDE, Key Vault without purge…

6 28d ago A 110 tokens original MIT

azure-redteam-easm

06

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill for External Attack Surface Management (EASM) during an Azure red team engagement. Discovers and correlates the internet-facing footprint — public IPs and FQDNs, internet-exposed management/data ports, dangling DNS records and subdomain-takeover risk, and orphaned assets not tied to a known in-scope…

6 28d ago A 117 tokens original MIT

azure-redteam-email

07

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this OPTIONAL skill to assess Microsoft 365 email security during a red team engagement when Exchange Online / M365 is in scope. Covers email authentication (SPF, DKIM, DMARC) via DNS, Exchange Online Protection and Microsoft Defender for Office 365 policies (anti-phishing, anti-spoofing, Safe Links, Safe…

6 28d ago A 119 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill for AUTHORIZED active external testing of internet-facing web apps and endpoints discovered in an Azure subscription, during a red team engagement. Covers OWASP Top 10 validation from the outside — missing security headers, weak TLS, insecure cookies, permissive CORS, risky HTTP methods, sensitive-path…

6 28d ago B 187 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to assess Azure governance and security posture during a red team engagement. Finds missing Azure Policy guardrails and over-broad exemptions, low Microsoft Defender for Cloud secure score and unactioned recommendations, weak management-group hierarchy and inherited guardrails, missing resource locks…

6 28d ago A 106 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to assess Microsoft Entra ID (Azure AD) and authentication security during an Azure red team engagement. Finds MFA gaps, Conditional Access weaknesses, legacy authentication, risky app registrations and service principal credentials, over-privileged Graph permissions, and risky guest access. Trigger…

6 28d ago A 86 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill during an Azure red team engagement to perform preflight reconnaissance — validate the caller's Azure permissions and build the shared resource inventory that the rest of the red team depends on. Trigger when starting an Azure assessment, running reconnaissance, enumerating Azure resources in scope, or…

6 28d ago A 86 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to assess Azure detection and monitoring coverage during a red team engagement — the blue-team blind spots that let an attacker operate unseen. Finds missing diagnostic settings, disabled activity-log retention, Key Vault/storage/NSG flow logs off, Defender for Cloud plans disabled, no Sentinel/SIEM…

6 28d ago A 98 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to assess Azure network security and internet-facing attack surface during a red team engagement. Finds public IPs, NSG rules exposing management/database ports to the internet, firewall misconfigurations, risky VNet peering, missing private endpoints, dangling DNS records (subdomain takeover), and…

6 28d ago A 89 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill when the user wants to run, coordinate, or manage an Azure cloud security penetration test or red team assessment against an Azure environment. This is the "Pentest Manager" that validates engagement scope, spins up the specialist red team, assigns reconnaissance and assessment tasks, and aggregates…

6 28d ago A 113 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to consolidate Azure red team findings into deduplicated, prioritized, client-ready deliverables at the end of an engagement. Normalizes raw findings against the finding schema, merges duplicates, applies the severity model, and renders an executive summary, a technical report, and per-finding write-ups…

6 28d ago A 92 tokens original MIT

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to assess Azure DevOps, CI/CD, and software-supply-chain security during a red team engagement. Finds workload identity federation (OIDC / federated credentials trusting GitHub Actions or Azure DevOps) with broad trust and Azure privilege, over-privileged pipeline service principals, deployment…

6 28d ago A 142 tokens original MIT

azure-redteam-web

17

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Use this skill to assess Azure web edge and static-site security during a red team engagement. Covers Azure Static Web Apps, Storage account static-website hosting, Front Door, CDN, Application Gateway (WAF posture), and API Management public exposure. Finds missing or detection-only WAF, weak/old TLS, HTTP not…

6 28d ago A 116 tokens original MIT

msgraph-sdk

18

Contoso-State/red-team-agent-orchestration

Skill Claude CodeCodex

Integrate Microsoft Graph SDK into any project — .NET, TypeScript/JavaScript, or Python. Covers auth patterns (client credentials, OBO, managed identity), SDK setup, calling Graph APIs, batching, delta queries, change notifications, throttling, and permission scopes. Use when accessing Microsoft 365 data (users, mail…

6 28d ago A 86 tokens original MIT

redteam-ai

19

Contoso-State/red-team-agent-orchestration

Agent Claude Code

AI and machine-learning security sub-agent for an Azure red team engagement. Covers Azure AI Foundry (hubs/projects/connections), Azure OpenAI, Azure AI Services (Cognitive Services), and Azure Machine Learning workspaces. Finds public network access, key-based auth instead of managed identity, disabled abuse/content…

6 28d ago A 92 tokens original MIT

Contoso-State/red-team-agent-orchestration

Agent Claude Code

Azure container and Kubernetes security sub-agent for a red team engagement. Owns AKS, ACR, Container Apps, and Container Instances — public API servers, local-admin kubeconfig, missing Entra/Azure RBAC, no network policy, Pod Security gaps, cluster-admin RBAC sprawl, node-MI exposure via IMDS, registry…

6 28d ago A 167 tokens original MIT

Contoso-State/red-team-agent-orchestration

Agent Claude Code

RBAC and privilege-escalation sub-agent for an Azure red team engagement. Analyzes role assignments, dangerous custom roles, escalation primitives, and managed identity abuse, then correlates findings across all domains into multi-step attack paths. Dispatched by the Red Team Orchestrator after the domain agents.

6 28d ago A 66 tokens original MIT

redteam-compute

22

Contoso-State/red-team-agent-orchestration

Agent Claude Code

Compute security sub-agent for an Azure red team engagement. Covers VMs, VMSS, App Service, and Functions. Finds disk encryption gaps, exposed managed identities, plaintext secrets, runCommand exposure, FTP/remote-debug, and missing auth. Containers and Kubernetes (AKS, ACR, Container Apps/Instances) are owned by the…

6 28d ago A 90 tokens original MIT

redteam-data

23

Contoso-State/red-team-agent-orchestration

Agent Claude Code

Data protection sub-agent for an Azure red team engagement. Covers Storage accounts, Key Vault, SQL/PostgreSQL/MySQL/Cosmos DB. Finds public blob access, weak database firewalls, missing TDE, Key Vault without purge protection, and over-permissive access. Dispatched by the Red Team Orchestrator.

6 28d ago A 69 tokens original MIT

redteam-easm

24

Contoso-State/red-team-agent-orchestration

Agent Claude Code

External Attack Surface Management sub-agent for an Azure red team engagement. Discovers and correlates the internet-facing footprint — public IPs and FQDNs, exposed management/data ports, dangling DNS records and subdomain-takeover risk, and assets not clearly tied to a known in-scope Azure resource. Consumes…

6 28d ago A 87 tokens original MIT