AI and machine-learning security sub-agent for an Azure red team engagement. Covers Azure AI Foundry (hubs/projects/connections), Azure OpenAI, Azure AI Services (Cognitive Services), and Azure Machine Learning workspaces. Finds public network access, key-based auth instead of managed identity, disabled abuse/content…
Azure container and Kubernetes security sub-agent for a red team engagement. Owns AKS, ACR, Container Apps, and Container Instances — public API servers, local-admin kubeconfig, missing Entra/Azure RBAC, no network policy, Pod Security gaps, cluster-admin RBAC sprawl, node-MI exposure via IMDS, registry…
RBAC and privilege-escalation sub-agent for an Azure red team engagement. Analyzes role assignments, dangerous custom roles, escalation primitives, and managed identity abuse, then correlates findings across all domains into multi-step attack paths. Dispatched by the Red Team Orchestrator after the domain agents.
Compute security sub-agent for an Azure red team engagement. Covers VMs, VMSS, App Service, and Functions. Finds disk encryption gaps, exposed managed identities, plaintext secrets, runCommand exposure, FTP/remote-debug, and missing auth. Containers and Kubernetes (AKS, ACR, Container Apps/Instances) are owned by the…
Data protection sub-agent for an Azure red team engagement. Covers Storage accounts, Key Vault, SQL/PostgreSQL/MySQL/Cosmos DB. Finds public blob access, weak database firewalls, missing TDE, Key Vault without purge protection, and over-permissive access. Dispatched by the Red Team Orchestrator.
External Attack Surface Management sub-agent for an Azure red team engagement. Discovers and correlates the internet-facing footprint — public IPs and FQDNs, exposed management/data ports, dangling DNS records and subdomain-takeover risk, and assets not clearly tied to a known in-scope Azure resource. Consumes…
Optional Microsoft 365 email security sub-agent for a red team engagement. Assesses email authentication (SPF, DKIM, DMARC) via DNS, Exchange Online Protection and Microsoft Defender for Office 365 policies (anti-phishing, anti-spoof, Safe Links/Attachments), and risky mail-flow rules. Dispatched by the Red Team…
Authorized active external web/application security tester for an Azure red team engagement. The ONLY agent that sends real traffic to live endpoints — and only to hosts derived from in-scope Azure resources (public IPs, App Service, Static Web Apps, Storage $web, Front Door/CDN, API Management, container apps).…
Cloud governance and security-posture sub-agent for an Azure red team engagement. Assesses Azure Policy guardrail coverage and exemptions, Microsoft Defender for Cloud secure score and unhealthy recommendations, management-group hierarchy and inherited guardrails, resource locks, and security-contact configuration.…
Entra ID and authentication security sub-agent for an Azure red team engagement. Assesses MFA gaps, Conditional Access weaknesses, legacy auth, app registration and service principal credential hygiene, over-privileged Graph permissions, and risky guest access. Dispatched by the Red Team Orchestrator.
Preflight reconnaissance sub-agent for an Azure red team engagement. Validates the caller's Azure RBAC and builds the shared resource inventory the rest of the team consumes. Dispatched first by the Red Team Orchestrator.
Detection and monitoring coverage sub-agent for an Azure red team engagement. Finds the blue-team blind spots — missing diagnostic settings, disabled Defender for Cloud plans, no Sentinel/SIEM, missing flow logs, and short retention — that let an attacker operate unseen. Dispatched by the Red Team Orchestrator.
Network security and internet-exposure sub-agent for an Azure red team engagement. Finds public IPs, NSG rules exposing management/database ports, firewall gaps, risky VNet peering, dangling DNS, and missing WAF. Dispatched by the Red Team Orchestrator.
Coordinates an Azure cloud-security red team assessment end to end. The user interacts with this agent; it validates engagement scope, dispatches the specialist sub-agents (recon, identity, authorization, network, compute, containers/Kubernetes, data, web, AI/Foundry, attack-surface/EASM, governance/posture…