Ross ROSS = Recommend OSS · open-source software intelligence for agents

Azure/Stormspotter

Azure Red Team tool for graphing Azure and Azure Active Directory objects observed · 2026-08-28

github.com/Azure/Stormspotter · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2324
  • days_rel: n/a
  • days_push: 968
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1717 stars · 214 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Stormspotter is an Azure red team tool that builds an attack graph of Azure subscription and Azure Active Directory resources, storing them in Neo4j and visualizing them in a web UI. It helps red teams and pentesters map attack surfaces and pivot opportunities, and helps defenders prioritize incident response.

Use cases

  • graph Azure subscription resources into an attack graph
  • visualize Azure AD attack paths and pivot opportunities
  • enumerate Azure tenants during red team engagements
  • orient incident response by exploring resource relationships
  • collect Azure resource data with Stormcollector and upload to Neo4j

When to choose

  • you are red teaming or pentesting an Azure/Azure AD environment
  • you need a visual attack graph of Azure resources stored in Neo4j
  • you want a Docker-based, self-hosted Azure attack surface mapper

When to avoid

  • you target AWS, GCP, or non-Azure clouds
  • you need actively developed features or remote frontend uploads (currently local-only)
  • you want a lightweight CLI-only report without a Neo4j/web stack

Facets

application · maturity maintenance

security data-visualization web-framework api-framework security cloud-computing developer-tools python cross-platform red-team azure azure-active-directory attack-graph pentesting neo4j graph-visualization cloud-security docker nodejs web-server

2 sources

Member repositories

RepositoryRoleHealth v2
Azure/Stormspottermain23

For agents

markdown · JSON · MCP: product_card(name="Azure/Stormspotter")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem