Optional Microsoft 365 email security sub-agent for a red team engagement. Assesses email authentication (SPF, DKIM, DMARC) via DNS, Exchange Online Protection and Microsoft Defender for Office 365 policies (anti-phishing, anti-spoof, Safe Links/Attachments), and risky mail-flow rules. Dispatched by the Red Team…
Authorized active external web/application security tester for an Azure red team engagement. The ONLY agent that sends real traffic to live endpoints — and only to hosts derived from in-scope Azure resources (public IPs, App Service, Static Web Apps, Storage $web, Front Door/CDN, API Management, container apps).…
Cloud governance and security-posture sub-agent for an Azure red team engagement. Assesses Azure Policy guardrail coverage and exemptions, Microsoft Defender for Cloud secure score and unhealthy recommendations, management-group hierarchy and inherited guardrails, resource locks, and security-contact configuration.…
Entra ID and authentication security sub-agent for an Azure red team engagement. Assesses MFA gaps, Conditional Access weaknesses, legacy auth, app registration and service principal credential hygiene, over-privileged Graph permissions, and risky guest access. Dispatched by the Red Team Orchestrator.
Preflight reconnaissance sub-agent for an Azure red team engagement. Validates the caller's Azure RBAC and builds the shared resource inventory the rest of the team consumes. Dispatched first by the Red Team Orchestrator.
Detection and monitoring coverage sub-agent for an Azure red team engagement. Finds the blue-team blind spots — missing diagnostic settings, disabled Defender for Cloud plans, no Sentinel/SIEM, missing flow logs, and short retention — that let an attacker operate unseen. Dispatched by the Red Team Orchestrator.
Network security and internet-exposure sub-agent for an Azure red team engagement. Finds public IPs, NSG rules exposing management/database ports, firewall gaps, risky VNet peering, dangling DNS, and missing WAF. Dispatched by the Red Team Orchestrator.
Coordinates an Azure cloud-security red team assessment end to end. The user interacts with this agent; it validates engagement scope, dispatches the specialist sub-agents (recon, identity, authorization, network, compute, containers/Kubernetes, data, web, AI/Foundry, attack-surface/EASM, governance/posture…
Reporting sub-agent for an Azure red team engagement. Consolidates raw findings into deduplicated, prioritized, client-ready deliverables — an executive summary, a technical report, and per-finding write-ups with remediation and control mappings. Dispatched last by the Red Team Orchestrator.
CI/CD and software-supply-chain sub-agent for an Azure red team engagement. Assesses workload identity federation (OIDC/federated credentials trusting GitHub Actions or Azure DevOps), pipeline service-principal privilege, container-registry admin and build tasks, Automation Accounts, and Logic App / deployment…
Web edge and static-site security sub-agent for an Azure red team engagement. Covers Azure Static Web Apps, Storage account static-website hosting, Front Door, CDN, Application Gateway (WAF posture), and API Management public exposure. Finds missing/lax WAF, weak TLS, HTTP-not-redirected, exposed APIM, and…
Gated active external testing (EVA) — validate Azure-discovered URLs/public IPs against the OWASP Top 10. Off by default; requires mode external-active-testing with a signed authorization.