Important
Not affiliated with Microsoft. Contoso‑State is an independent, personal demonstration organization. It is not affiliated with, endorsed by, or sponsored by Microsoft. "Contoso" is a fictitious company name Microsoft uses throughout its own samples and documentation — it is used here only in that same demonstration spirit. "Microsoft", "Azure", and related names are trademarks of Microsoft Corporation. Everything published here is provided for demonstration and educational purposes only.
A home for hands-on, open-source experiments in cloud security and agentic AI — built to demonstrate ideas, share reference implementations, and explore what coordinated teams of AI agents can do safely. Opinions and projects here are the author's own.
An agentic, read-only red team for Microsoft Azure. A Pentest Manager orchestrates a team of fifteen domain specialists across identity, RBAC, network exposure, compute, and Kubernetes, then correlates their findings into real attack paths and a leadership-ready report. The same team runs natively on GitHub Copilot CLI, Claude Code, OpenAI Codex CLI, and Cursor — all backed by one shared guard core that denies any state-changing action.
📖 Documentation & demo: https://contoso-state.github.io/red-team-agent-orchestration/
💻 Source: https://github.com/Contoso-State/red-team-agent-orchestration
These projects use AI agents, which can make mistakes — including generating false positives and missing real issues. Everything here is a starting point, not a substitute for professional human review. Use at your own risk, ensure you are properly authorized, and independently validate all findings before acting on them.
Unless stated otherwise, projects in this organization are released under the MIT License.