# Azure/Stormspotter

Azure Red Team tool for graphing Azure and Azure Active Directory objects

Repository: https://github.com/Azure/Stormspotter
Canonical: https://ross.abutalabs.com/products/stormspotter
Language: Python
License: MIT
License Family: permissive
Last push: 2024-01-08T17:20:05+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2324, "days_push": 968, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1717, forks 214 (observed 2026-08-28T04:05:26.431041+00:00)

## What it is
Stormspotter is an Azure red team tool that builds an attack graph of Azure subscription and Azure Active Directory resources, storing them in Neo4j and visualizing them in a web UI. It helps red teams and pentesters map attack surfaces and pivot opportunities, and helps defenders prioritize incident response.

## Use cases
- graph Azure subscription resources into an attack graph
- visualize Azure AD attack paths and pivot opportunities
- enumerate Azure tenants during red team engagements
- orient incident response by exploring resource relationships
- collect Azure resource data with Stormcollector and upload to Neo4j

## When to choose
- you are red teaming or pentesting an Azure/Azure AD environment
- you need a visual attack graph of Azure resources stored in Neo4j
- you want a Docker-based, self-hosted Azure attack surface mapper

## When to avoid
- you target AWS, GCP, or non-Azure clouds
- you need actively developed features or remote frontend uploads (currently local-only)
- you want a lightweight CLI-only report without a Neo4j/web stack

## Facets
- artifact type: application
- maturity: maintenance
- function: security, data-visualization, web-framework, api-framework
- domain: security, cloud-computing, developer-tools
- platform: python, cross-platform
- tags: red-team, azure, azure-active-directory, attack-graph, pentesting, neo4j, graph-visualization, cloud-security, docker, nodejs, web-server

## Member repositories
- Azure/Stormspotter (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:26.431041+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:34:11.699188+00:00, confidence not recorded.
  - readme: https://github.com/Azure/Stormspotter (fetched 2026-08-28T04:05:26.431041+00:00, sha 5669d8f8dbbb)
  - registry_pypi: https://pypi.org/pypi/stormspotter/json (fetched 2026-08-29T11:10:08.344107+00:00, sha 58e40a167b93)
- Data as of 2026-08-30T08:39:29.467469+00:00.
