Skip to main content

Contoso-State/red-team-agent-orchestration

SkillsMP는 Contoso-State/red-team-agent-orchestration에서 17개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
17
GitHub 스타
6
GitHub 포크
1

이 저장소의 skills

직업 카테고리 1개 · 100% 분류됨

수집된 skill 17개 중 17개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Use this skill when the user wants to run, coordinate, or manage an Azure cloud security penetration test or red team assessment against an Azure environment. This is the "Pentest Manager" that validates engagement scope, spins up the specialist red team,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to assess Azure AI and machine-learning security during a red team engagement. Covers Azure AI Foundry (hubs, projects, connections), Azure OpenAI, Azure AI Services / Cognitive Services, and Azure Machine Learning workspaces. Finds public…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to assess Azure container and Kubernetes security during a red team engagement. Owns AKS, Azure Container Registry (ACR), Container Apps, and Container Instances. Finds public API servers, local-admin kubeconfig, missing Entra/Azure RBAC for…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to analyze Azure RBAC and map privilege escalation and lateral movement attack paths during an Azure red team engagement. Finds over-permissioned roles, dangerous custom roles, escalation primitives (roleAssignments/write, runCommand,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to assess Azure compute security during a red team engagement. Covers VMs, VM Scale Sets, App Service, and Functions. Finds unmanaged disk encryption, exposed managed identities, insecure custom script extensions, runCommand exposure, remote…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to assess Azure data protection security during a red team engagement. Covers Storage accounts, Key Vault, SQL/PostgreSQL/MySQL/Cosmos DB. Finds public blob containers, anonymous access, shared-key auth, permissive SQL firewall rules (0.0.0.0 /…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill for External Attack Surface Management (EASM) during an Azure red team engagement. Discovers and correlates the internet-facing footprint — public IPs and FQDNs, internet-exposed management/data ports, dangling DNS records and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this OPTIONAL skill to assess Microsoft 365 email security during a red team engagement when Exchange Online / M365 is in scope. Covers email authentication (SPF, DKIM, DMARC) via DNS, Exchange Online Protection and Microsoft Defender for Office 365…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill for AUTHORIZED active external testing of internet-facing web apps and endpoints discovered in an Azure subscription, during a red team engagement. Covers OWASP Top 10 validation from the outside — missing security headers, weak TLS, insecure…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to assess Azure governance and security posture during a red team engagement. Finds missing Azure Policy guardrails and over-broad exemptions, low Microsoft Defender for Cloud secure score and unactioned recommendations, weak management-group…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to assess Microsoft Entra ID (Azure AD) and authentication security during an Azure red team engagement. Finds MFA gaps, Conditional Access weaknesses, legacy authentication, risky app registrations and service principal credentials,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill during an Azure red team engagement to perform preflight reconnaissance — validate the caller's Azure permissions and build the shared resource inventory that the rest of the red team depends on. Trigger when starting an Azure assessment,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to assess Azure detection and monitoring coverage during a red team engagement — the blue-team blind spots that let an attacker operate unseen. Finds missing diagnostic settings, disabled activity-log retention, Key Vault/storage/NSG flow logs…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to assess Azure network security and internet-facing attack surface during a red team engagement. Finds public IPs, NSG rules exposing management/database ports to the internet, firewall misconfigurations, risky VNet peering, missing private…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to consolidate Azure red team findings into deduplicated, prioritized, client-ready deliverables at the end of an engagement. Normalizes raw findings against the finding schema, merges duplicates, applies the severity model, and renders an…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to assess Azure DevOps, CI/CD, and software-supply-chain security during a red team engagement. Finds workload identity federation (OIDC / federated credentials trusting GitHub Actions or Azure DevOps) with broad trust and Azure privilege,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill to assess Azure web edge and static-site security during a red team engagement. Covers Azure Static Web Apps, Storage account static-website hosting, Front Door, CDN, Application Gateway (WAF posture), and API Management public exposure. Finds…

원문 언어: 영어

업데이트
수집된 skill 17개 중 17개를 표시합니다.