Contoso-State

62 mods across 1 repository, 6 stars between them.

redteam-ai

49

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

AI and machine-learning security sub-agent for an Azure red team engagement. Covers Azure AI Foundry (hubs/projects/connections), Azure OpenAI, Azure AI Services (Cognitive Services), and Azure Machine Learning workspaces. Finds public network access, key-based auth instead of managed identity, disabled abuse/content…

6 29d ago A 88 tokens original MIT

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Azure container and Kubernetes security sub-agent for a red team engagement. Owns AKS, ACR, Container Apps, and Container Instances — public API servers, local-admin kubeconfig, missing Entra/Azure RBAC, no network policy, Pod Security gaps, cluster-admin RBAC sprawl, node-MI exposure via IMDS, registry…

6 29d ago A 161 tokens original MIT

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

RBAC and privilege-escalation sub-agent for an Azure red team engagement. Analyzes role assignments, dangerous custom roles, escalation primitives, and managed identity abuse, then correlates findings across all domains into multi-step attack paths. Dispatched by the Red Team Orchestrator after the domain agents.

6 29d ago A 61 tokens original MIT

redteam-compute

52

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Compute security sub-agent for an Azure red team engagement. Covers VMs, VMSS, App Service, and Functions. Finds disk encryption gaps, exposed managed identities, plaintext secrets, runCommand exposure, FTP/remote-debug, and missing auth. Containers and Kubernetes (AKS, ACR, Container Apps/Instances) are owned by the…

6 29d ago A 85 tokens original MIT

redteam-data

53

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Data protection sub-agent for an Azure red team engagement. Covers Storage accounts, Key Vault, SQL/PostgreSQL/MySQL/Cosmos DB. Finds public blob access, weak database firewalls, missing TDE, Key Vault without purge protection, and over-permissive access. Dispatched by the Red Team Orchestrator.

6 29d ago A 65 tokens original MIT

redteam-easm

54

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

External Attack Surface Management sub-agent for an Azure red team engagement. Discovers and correlates the internet-facing footprint — public IPs and FQDNs, exposed management/data ports, dangling DNS records and subdomain-takeover risk, and assets not clearly tied to a known in-scope Azure resource. Consumes…

6 29d ago A 82 tokens original MIT

redteam-email

55

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Optional Microsoft 365 email security sub-agent for a red team engagement. Assesses email authentication (SPF, DKIM, DMARC) via DNS, Exchange Online Protection and Microsoft Defender for Office 365 policies (anti-phishing, anti-spoof, Safe Links/Attachments), and risky mail-flow rules. Dispatched by the Red Team…

6 29d ago A 85 tokens original MIT

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Authorized active external web/application security tester for an Azure red team engagement. The ONLY agent that sends real traffic to live endpoints — and only to hosts derived from in-scope Azure resources (public IPs, App Service, Static Web Apps, Storage $web, Front Door/CDN, API Management, container apps).…

6 29d ago A 152 tokens original MIT

redteam-governance

57

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Cloud governance and security-posture sub-agent for an Azure red team engagement. Assesses Azure Policy guardrail coverage and exemptions, Microsoft Defender for Cloud secure score and unhealthy recommendations, management-group hierarchy and inherited guardrails, resource locks, and security-contact configuration.…

6 29d ago A 87 tokens original MIT

redteam-identity

58

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Entra ID and authentication security sub-agent for an Azure red team engagement. Assesses MFA gaps, Conditional Access weaknesses, legacy auth, app registration and service principal credential hygiene, over-privileged Graph permissions, and risky guest access. Dispatched by the Red Team Orchestrator.

6 29d ago B 57 tokens original MIT

redteam-inventory

59

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Preflight reconnaissance sub-agent for an Azure red team engagement. Validates the caller's Azure RBAC and builds the shared resource inventory the rest of the team consumes. Dispatched first by the Red Team Orchestrator.

6 29d ago A 44 tokens original MIT

redteam-logging

60

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Detection and monitoring coverage sub-agent for an Azure red team engagement. Finds the blue-team blind spots — missing diagnostic settings, disabled Defender for Cloud plans, no Sentinel/SIEM, missing flow logs, and short retention — that let an attacker operate unseen. Dispatched by the Red Team Orchestrator.

6 29d ago A 61 tokens original MIT

redteam-network

61

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Network security and internet-exposure sub-agent for an Azure red team engagement. Finds public IPs, NSG rules exposing management/database ports, firewall gaps, risky VNet peering, dangling DNS, and missing WAF. Dispatched by the Red Team Orchestrator.

6 29d ago A 55 tokens original MIT

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Coordinates an Azure cloud-security red team assessment end to end. The user interacts with this agent; it validates engagement scope, dispatches the specialist sub-agents (recon, identity, authorization, network, compute, containers/Kubernetes, data, web, AI/Foundry, attack-surface/EASM, governance/posture…

6 29d ago A 155 tokens original MIT