Skip to main content

Contoso-State/red-team-agent-orchestration

SkillsMP has collected 17 skills from Contoso-State/red-team-agent-orchestration. Open a skill to review its source and details.

Latest recorded source activity
SkillsMP catalog refreshed
skills collected
17
GitHub stars
6
GitHub forks
1

Skills in this repository

1 occupation categories · 100% classified

Showing 17 of 17 collected skills.

occupation
Information Security Analysts
description

Use this skill when the user wants to run, coordinate, or manage an Azure cloud security penetration test or red team assessment against an Azure environment. This is the "Pentest Manager" that validates engagement scope, spins up the specialist red team,…

updated
occupation
Information Security Analysts
description

Use this skill to assess Azure AI and machine-learning security during a red team engagement. Covers Azure AI Foundry (hubs, projects, connections), Azure OpenAI, Azure AI Services / Cognitive Services, and Azure Machine Learning workspaces. Finds public…

updated
occupation
Information Security Analysts
description

Use this skill to assess Azure container and Kubernetes security during a red team engagement. Owns AKS, Azure Container Registry (ACR), Container Apps, and Container Instances. Finds public API servers, local-admin kubeconfig, missing Entra/Azure RBAC for…

updated
occupation
Information Security Analysts
description

Use this skill to analyze Azure RBAC and map privilege escalation and lateral movement attack paths during an Azure red team engagement. Finds over-permissioned roles, dangerous custom roles, escalation primitives (roleAssignments/write, runCommand,…

updated
occupation
Information Security Analysts
description

Use this skill to assess Azure compute security during a red team engagement. Covers VMs, VM Scale Sets, App Service, and Functions. Finds unmanaged disk encryption, exposed managed identities, insecure custom script extensions, runCommand exposure, remote…

updated
occupation
Information Security Analysts
description

Use this skill to assess Azure data protection security during a red team engagement. Covers Storage accounts, Key Vault, SQL/PostgreSQL/MySQL/Cosmos DB. Finds public blob containers, anonymous access, shared-key auth, permissive SQL firewall rules (0.0.0.0 /…

updated
occupation
Information Security Analysts
description

Use this skill for External Attack Surface Management (EASM) during an Azure red team engagement. Discovers and correlates the internet-facing footprint — public IPs and FQDNs, internet-exposed management/data ports, dangling DNS records and…

updated
occupation
Information Security Analysts
description

Use this OPTIONAL skill to assess Microsoft 365 email security during a red team engagement when Exchange Online / M365 is in scope. Covers email authentication (SPF, DKIM, DMARC) via DNS, Exchange Online Protection and Microsoft Defender for Office 365…

updated
occupation
Information Security Analysts
description

Use this skill for AUTHORIZED active external testing of internet-facing web apps and endpoints discovered in an Azure subscription, during a red team engagement. Covers OWASP Top 10 validation from the outside — missing security headers, weak TLS, insecure…

updated
occupation
Information Security Analysts
description

Use this skill to assess Azure governance and security posture during a red team engagement. Finds missing Azure Policy guardrails and over-broad exemptions, low Microsoft Defender for Cloud secure score and unactioned recommendations, weak management-group…

updated
occupation
Information Security Analysts
description

Use this skill to assess Microsoft Entra ID (Azure AD) and authentication security during an Azure red team engagement. Finds MFA gaps, Conditional Access weaknesses, legacy authentication, risky app registrations and service principal credentials,…

updated
occupation
Information Security Analysts
description

Use this skill during an Azure red team engagement to perform preflight reconnaissance — validate the caller's Azure permissions and build the shared resource inventory that the rest of the red team depends on. Trigger when starting an Azure assessment,…

updated
occupation
Information Security Analysts
description

Use this skill to assess Azure detection and monitoring coverage during a red team engagement — the blue-team blind spots that let an attacker operate unseen. Finds missing diagnostic settings, disabled activity-log retention, Key Vault/storage/NSG flow logs…

updated
occupation
Information Security Analysts
description

Use this skill to assess Azure network security and internet-facing attack surface during a red team engagement. Finds public IPs, NSG rules exposing management/database ports to the internet, firewall misconfigurations, risky VNet peering, missing private…

updated
occupation
Information Security Analysts
description

Use this skill to consolidate Azure red team findings into deduplicated, prioritized, client-ready deliverables at the end of an engagement. Normalizes raw findings against the finding schema, merges duplicates, applies the severity model, and renders an…

updated
occupation
Information Security Analysts
description

Use this skill to assess Azure DevOps, CI/CD, and software-supply-chain security during a red team engagement. Finds workload identity federation (OIDC / federated credentials trusting GitHub Actions or Azure DevOps) with broad trust and Azure privilege,…

updated
occupation
Information Security Analysts
description

Use this skill to assess Azure web edge and static-site security during a red team engagement. Covers Azure Static Web Apps, Storage account static-website hosting, Front Door, CDN, Application Gateway (WAF posture), and API Management public exposure. Finds…

updated
Showing 17 of 17 collected skills.