Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Azure red team engagement — read-only posture and guardrails (always applied).
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Azure red team engagement — read-only posture and guardrails (always applied).
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Azure red team — canonical graph orchestration standard (always applied).
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
AI and machine-learning security sub-agent for an Azure red team engagement. Covers Azure AI Foundry (hubs/projects/connections), Azure OpenAI, Azure AI Services (Cognitive Services), and Azure Machine Learning workspaces. Finds public network access, key-based auth instead of managed identity, disabled abuse/content…
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Azure container and Kubernetes security sub-agent for a red team engagement. Owns AKS, ACR, Container Apps, and Container Instances — public API servers, local-admin kubeconfig, missing Entra/Azure RBAC, no network policy, Pod Security gaps, cluster-admin RBAC sprawl, node-MI exposure via IMDS, registry…
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
RBAC and privilege-escalation sub-agent for an Azure red team engagement. Analyzes role assignments, dangerous custom roles, escalation primitives, and managed identity abuse, then correlates findings across all domains into multi-step attack paths. Dispatched by the Red Team Orchestrator after the domain agents.
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Compute security sub-agent for an Azure red team engagement. Covers VMs, VMSS, App Service, and Functions. Finds disk encryption gaps, exposed managed identities, plaintext secrets, runCommand exposure, FTP/remote-debug, and missing auth. Containers and Kubernetes (AKS, ACR, Container Apps/Instances) are owned by the…
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Data protection sub-agent for an Azure red team engagement. Covers Storage accounts, Key Vault, SQL/PostgreSQL/MySQL/Cosmos DB. Finds public blob access, weak database firewalls, missing TDE, Key Vault without purge protection, and over-permissive access. Dispatched by the Red Team Orchestrator.
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
External Attack Surface Management sub-agent for an Azure red team engagement. Discovers and correlates the internet-facing footprint — public IPs and FQDNs, exposed management/data ports, dangling DNS records and subdomain-takeover risk, and assets not clearly tied to a known in-scope Azure resource. Consumes…
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Optional Microsoft 365 email security sub-agent for a red team engagement. Assesses email authentication (SPF, DKIM, DMARC) via DNS, Exchange Online Protection and Microsoft Defender for Office 365 policies (anti-phishing, anti-spoof, Safe Links/Attachments), and risky mail-flow rules. Dispatched by the Red Team…
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Authorized active external web/application security tester for an Azure red team engagement. The ONLY agent that sends real traffic to live endpoints — and only to hosts derived from in-scope Azure resources (public IPs, App Service, Static Web Apps, Storage $web, Front Door/CDN, API Management, container apps).…
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Cloud governance and security-posture sub-agent for an Azure red team engagement. Assesses Azure Policy guardrail coverage and exemptions, Microsoft Defender for Cloud secure score and unhealthy recommendations, management-group hierarchy and inherited guardrails, resource locks, and security-contact configuration.…
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Entra ID and authentication security sub-agent for an Azure red team engagement. Assesses MFA gaps, Conditional Access weaknesses, legacy auth, app registration and service principal credential hygiene, over-privileged Graph permissions, and risky guest access. Dispatched by the Red Team Orchestrator.
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Preflight reconnaissance sub-agent for an Azure red team engagement. Validates the caller's Azure RBAC and builds the shared resource inventory the rest of the team consumes. Dispatched first by the Red Team Orchestrator.
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Detection and monitoring coverage sub-agent for an Azure red team engagement. Finds the blue-team blind spots — missing diagnostic settings, disabled Defender for Cloud plans, no Sentinel/SIEM, missing flow logs, and short retention — that let an attacker operate unseen. Dispatched by the Red Team Orchestrator.
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Network security and internet-exposure sub-agent for an Azure red team engagement. Finds public IPs, NSG rules exposing management/database ports, firewall gaps, risky VNet peering, dangling DNS, and missing WAF. Dispatched by the Red Team Orchestrator.
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Coordinates an Azure cloud-security red team assessment end to end. The user interacts with this agent; it validates engagement scope, dispatches the specialist sub-agents (recon, identity, authorization, network, compute, containers/Kubernetes, data, web, AI/Foundry, attack-surface/EASM, governance/posture…
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Reporting sub-agent for an Azure red team engagement. Consolidates raw findings into deduplicated, prioritized, client-ready deliverables — an executive summary, a technical report, and per-finding write-ups with remediation and control mappings. Dispatched last by the Red Team Orchestrator.
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
CI/CD and software-supply-chain sub-agent for an Azure red team engagement. Assesses workload identity federation (OIDC/federated credentials trusting GitHub Actions or Azure DevOps), pipeline service-principal privilege, container-registry admin and build tasks, Automation Accounts, and Logic App / deployment…
Contoso-State/red-team-agent-orchestration
Cursor rule Cursor
Web edge and static-site security sub-agent for an Azure red team engagement. Covers Azure Static Web Apps, Storage account static-website hosting, Front Door, CDN, Application Gateway (WAF posture), and API Management public exposure. Finds missing/lax WAF, weak TLS, HTTP-not-redirected, exposed APIM, and…
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: