Contoso-State/red-team-agent-orchestration

6Stars on the repository
66Mods indexed here, across every type
todayLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

redteam-ai

03

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

AI and machine-learning security sub-agent for an Azure red team engagement. Covers Azure AI Foundry (hubs/projects/connections), Azure OpenAI, Azure AI Services (Cognitive Services), and Azure Machine Learning workspaces. Finds public network access, key-based auth instead of managed identity, disabled abuse/content…

not rated 6 today A 88 tokens original MIT

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Azure container and Kubernetes security sub-agent for a red team engagement. Owns AKS, ACR, Container Apps, and Container Instances — public API servers, local-admin kubeconfig, missing Entra/Azure RBAC, no network policy, Pod Security gaps, cluster-admin RBAC sprawl, node-MI exposure via IMDS, registry…

not rated 6 today A 161 tokens original MIT

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

RBAC and privilege-escalation sub-agent for an Azure red team engagement. Analyzes role assignments, dangerous custom roles, escalation primitives, and managed identity abuse, then correlates findings across all domains into multi-step attack paths. Dispatched by the Red Team Orchestrator after the domain agents.

not rated 6 today A 61 tokens original MIT

redteam-compute

06

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Compute security sub-agent for an Azure red team engagement. Covers VMs, VMSS, App Service, and Functions. Finds disk encryption gaps, exposed managed identities, plaintext secrets, runCommand exposure, FTP/remote-debug, and missing auth. Containers and Kubernetes (AKS, ACR, Container Apps/Instances) are owned by the…

not rated 6 today A 85 tokens original MIT

redteam-data

07

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Data protection sub-agent for an Azure red team engagement. Covers Storage accounts, Key Vault, SQL/PostgreSQL/MySQL/Cosmos DB. Finds public blob access, weak database firewalls, missing TDE, Key Vault without purge protection, and over-permissive access. Dispatched by the Red Team Orchestrator.

not rated 6 today A 65 tokens original MIT

redteam-easm

08

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

External Attack Surface Management sub-agent for an Azure red team engagement. Discovers and correlates the internet-facing footprint — public IPs and FQDNs, exposed management/data ports, dangling DNS records and subdomain-takeover risk, and assets not clearly tied to a known in-scope Azure resource. Consumes…

not rated 6 today A 82 tokens original MIT

redteam-email

09

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Optional Microsoft 365 email security sub-agent for a red team engagement. Assesses email authentication (SPF, DKIM, DMARC) via DNS, Exchange Online Protection and Microsoft Defender for Office 365 policies (anti-phishing, anti-spoof, Safe Links/Attachments), and risky mail-flow rules. Dispatched by the Red Team…

not rated 6 today A 85 tokens original MIT

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Authorized active external web/application security tester for an Azure red team engagement. The ONLY agent that sends real traffic to live endpoints — and only to hosts derived from in-scope Azure resources (public IPs, App Service, Static Web Apps, Storage $web, Front Door/CDN, API Management, container apps).…

not rated 6 today A 152 tokens original MIT

redteam-governance

11

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Cloud governance and security-posture sub-agent for an Azure red team engagement. Assesses Azure Policy guardrail coverage and exemptions, Microsoft Defender for Cloud secure score and unhealthy recommendations, management-group hierarchy and inherited guardrails, resource locks, and security-contact configuration.…

not rated 6 today A 87 tokens original MIT

redteam-identity

12

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Entra ID and authentication security sub-agent for an Azure red team engagement. Assesses MFA gaps, Conditional Access weaknesses, legacy auth, app registration and service principal credential hygiene, over-privileged Graph permissions, and risky guest access. Dispatched by the Red Team Orchestrator.

not rated 6 today B 57 tokens original MIT

redteam-inventory

13

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Preflight reconnaissance sub-agent for an Azure red team engagement. Validates the caller's Azure RBAC and builds the shared resource inventory the rest of the team consumes. Dispatched first by the Red Team Orchestrator.

not rated 6 today A 44 tokens original MIT

redteam-logging

14

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Detection and monitoring coverage sub-agent for an Azure red team engagement. Finds the blue-team blind spots — missing diagnostic settings, disabled Defender for Cloud plans, no Sentinel/SIEM, missing flow logs, and short retention — that let an attacker operate unseen. Dispatched by the Red Team Orchestrator.

not rated 6 today A 61 tokens original MIT

redteam-network

15

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Network security and internet-exposure sub-agent for an Azure red team engagement. Finds public IPs, NSG rules exposing management/database ports, firewall gaps, risky VNet peering, dangling DNS, and missing WAF. Dispatched by the Red Team Orchestrator.

not rated 6 today A 55 tokens original MIT

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Coordinates an Azure cloud-security red team assessment end to end. The user interacts with this agent; it validates engagement scope, dispatches the specialist sub-agents (recon, identity, authorization, network, compute, containers/Kubernetes, data, web, AI/Foundry, attack-surface/EASM, governance/posture…

not rated 6 today A 155 tokens original MIT

redteam-reporting

17

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Reporting sub-agent for an Azure red team engagement. Consolidates raw findings into deduplicated, prioritized, client-ready deliverables — an executive summary, a technical report, and per-finding write-ups with remediation and control mappings. Dispatched last by the Red Team Orchestrator.

not rated 6 today A 57 tokens original MIT

redteam-supplychain

18

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

CI/CD and software-supply-chain sub-agent for an Azure red team engagement. Assesses workload identity federation (OIDC/federated credentials trusting GitHub Actions or Azure DevOps), pipeline service-principal privilege, container-registry admin and build tasks, Automation Accounts, and Logic App / deployment…

not rated 6 today A 95 tokens original MIT

redteam-web

19

Contoso-State/red-team-agent-orchestration

Cursor rule Cursor

Web edge and static-site security sub-agent for an Azure red team engagement. Covers Azure Static Web Apps, Storage account static-website hosting, Front Door, CDN, Application Gateway (WAF posture), and API Management public exposure. Finds missing/lax WAF, weak TLS, HTTP-not-redirected, exposed APIM, and…

not rated 6 today A 83 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: