Use this skill to assess Azure AI and machine-learning security during a red team engagement. Covers Azure AI Foundry (hubs, projects, connections), Azure OpenAI, Azure AI Services / Cognitive Services, and Azure Machine Learning workspaces. Finds public network access on AI endpoints, key-based auth instead of…
Use this skill to assess Azure container and Kubernetes security during a red team engagement. Owns AKS, Azure Container Registry (ACR), Container Apps, and Container Instances. Finds public API servers, local-admin kubeconfig, missing Entra/Azure RBAC for Kubernetes, no network policy, Pod Security Admission gaps…
Use this skill to analyze Azure RBAC and map privilege escalation and lateral movement attack paths during an Azure red team engagement. Finds over-permissioned roles, dangerous custom roles, escalation primitives (roleAssignments/write, runCommand, listClusterAdminCredential), managed identity abuse, and correlates…
Use this skill to assess Azure compute security during a red team engagement. Covers VMs, VM Scale Sets, App Service, and Functions. Finds unmanaged disk encryption, exposed managed identities, insecure custom script extensions, runCommand exposure, remote debugging, missing auth, plaintext secrets in app settings…
Use this skill to assess Azure data protection security during a red team engagement. Covers Storage accounts, Key Vault, SQL/PostgreSQL/MySQL/Cosmos DB. Finds public blob containers, anonymous access, shared-key auth, permissive SQL firewall rules (0.0.0.0 / allow Azure services), missing TDE, Key Vault without purge…
Use this skill for External Attack Surface Management (EASM) during an Azure red team engagement. Discovers and correlates the internet-facing footprint — public IPs and FQDNs, internet-exposed management/data ports, dangling DNS records and subdomain-takeover risk, and orphaned assets not tied to a known in-scope…
Use this OPTIONAL skill to assess Microsoft 365 email security during a red team engagement when Exchange Online / M365 is in scope. Covers email authentication (SPF, DKIM, DMARC) via DNS, Exchange Online Protection and Microsoft Defender for Office 365 policies (anti-phishing, anti-spoofing, Safe Links, Safe…
Use this skill for AUTHORIZED active external testing of internet-facing web apps and endpoints discovered in an Azure subscription, during a red team engagement. Covers OWASP Top 10 validation from the outside — missing security headers, weak TLS, insecure cookies, permissive CORS, risky HTTP methods, sensitive-path…
Use this skill to assess Azure governance and security posture during a red team engagement. Finds missing Azure Policy guardrails and over-broad exemptions, low Microsoft Defender for Cloud secure score and unactioned recommendations, weak management-group hierarchy and inherited guardrails, missing resource locks…
Use this skill to assess Microsoft Entra ID (Azure AD) and authentication security during an Azure red team engagement. Finds MFA gaps, Conditional Access weaknesses, legacy authentication, risky app registrations and service principal credentials, over-privileged Graph permissions, and risky guest access. Trigger…
Use this skill during an Azure red team engagement to perform preflight reconnaissance — validate the caller's Azure permissions and build the shared resource inventory that the rest of the red team depends on. Trigger when starting an Azure assessment, running reconnaissance, enumerating Azure resources in scope, or…
Use this skill to assess Azure detection and monitoring coverage during a red team engagement — the blue-team blind spots that let an attacker operate unseen. Finds missing diagnostic settings, disabled activity-log retention, Key Vault/storage/NSG flow logs off, Defender for Cloud plans disabled, no Sentinel/SIEM…
Use this skill to assess Azure network security and internet-facing attack surface during a red team engagement. Finds public IPs, NSG rules exposing management/database ports to the internet, firewall misconfigurations, risky VNet peering, missing private endpoints, dangling DNS records (subdomain takeover), and…
Use this skill when the user wants to run, coordinate, or manage an Azure cloud security penetration test or red team assessment against an Azure environment. This is the "Pentest Manager" that validates engagement scope, spins up the specialist red team, assigns reconnaissance and assessment tasks, and aggregates…
Use this skill to consolidate Azure red team findings into deduplicated, prioritized, client-ready deliverables at the end of an engagement. Normalizes raw findings against the finding schema, merges duplicates, applies the severity model, and renders an executive summary, a technical report, and per-finding write-ups…
Use this skill to assess Azure DevOps, CI/CD, and software-supply-chain security during a red team engagement. Finds workload identity federation (OIDC / federated credentials trusting GitHub Actions or Azure DevOps) with broad trust and Azure privilege, over-privileged pipeline service principals, deployment…
Use this skill to assess Azure web edge and static-site security during a red team engagement. Covers Azure Static Web Apps, Storage account static-website hosting, Front Door, CDN, Application Gateway (WAF posture), and API Management public exposure. Finds missing or detection-only WAF, weak/old TLS, HTTP not…
Integrate Microsoft Graph SDK into any project — .NET, TypeScript/JavaScript, or Python. Covers auth patterns (client credentials, OBO, managed identity), SDK setup, calling Graph APIs, batching, delta queries, change notifications, throttling, and permission scopes. Use when accessing Microsoft 365 data (users, mail…
AI and machine-learning security sub-agent for an Azure red team engagement. Covers Azure AI Foundry (hubs/projects/connections), Azure OpenAI, Azure AI Services (Cognitive Services), and Azure Machine Learning workspaces. Finds public network access, key-based auth instead of managed identity, disabled abuse/content…
Azure container and Kubernetes security sub-agent for a red team engagement. Owns AKS, ACR, Container Apps, and Container Instances — public API servers, local-admin kubeconfig, missing Entra/Azure RBAC, no network policy, Pod Security gaps, cluster-admin RBAC sprawl, node-MI exposure via IMDS, registry…
RBAC and privilege-escalation sub-agent for an Azure red team engagement. Analyzes role assignments, dangerous custom roles, escalation primitives, and managed identity abuse, then correlates findings across all domains into multi-step attack paths. Dispatched by the Red Team Orchestrator after the domain agents.
Compute security sub-agent for an Azure red team engagement. Covers VMs, VMSS, App Service, and Functions. Finds disk encryption gaps, exposed managed identities, plaintext secrets, runCommand exposure, FTP/remote-debug, and missing auth. Containers and Kubernetes (AKS, ACR, Container Apps/Instances) are owned by the…
Data protection sub-agent for an Azure red team engagement. Covers Storage accounts, Key Vault, SQL/PostgreSQL/MySQL/Cosmos DB. Finds public blob access, weak database firewalls, missing TDE, Key Vault without purge protection, and over-permissive access. Dispatched by the Red Team Orchestrator.
External Attack Surface Management sub-agent for an Azure red team engagement. Discovers and correlates the internet-facing footprint — public IPs and FQDNs, exposed management/data ports, dangling DNS records and subdomain-takeover risk, and assets not clearly tied to a known in-scope Azure resource. Consumes…