{"repo":"labyrinthinesecurity/silhouette","free":true,"listed":false,"github":"https://github.com/labyrinthinesecurity/silhouette","clone":"git clone https://github.com/labyrinthinesecurity/silhouette.git","description":"An Azure SPN access minimizer","language":"Python","stars":48,"topics":["automation","azure","devsecops","iam"],"license":null,"category":"workflow-automation","readme_excerpt":"Azure Silhouette, a SPN sorter and roles minimizer NHI Rank (new) Silhouette now includes NHI Rank , located in the NHI rank/ subdirectory. Overview NHI Rank is an interactive visualization tool that displays fiber and NHI data through a hierarchical drill-down interface. It uses a terminal-based curses UI to show statistical distributions and detailed listings of fibers and their constituent NHIs. This makes it easy to identify the most critical identities , even with tens of thousands of NHIs. The compression comes from fibration theory: NHIs with identical privilege structures collapse into the same fiber, yielding an extremely compact risk topology. Usage Pre-requisites First, run silhouette in --frs mode (see below to understand this mode), then generate today's fibers or the fibers of a previous date (YYYY-MM-DD): If you didnt run silhouette on YYYY-MM-DD, then gen fibers.py will not work on this date. You are now ready to launch NHI rank. Command-line Options Input Files (non-demo mode) - sorted NHIs YYYY-MM-DD.csv - NHI data with risk metrics - sorted fibers YYYY-MM-DD.csv - Fiber groupings with blast radius Output (non-interactive mode) Displays a sorted table of fibers with: - Fiber ID - Representative NHI name - κ (kappa equivalent) - WAR (Weighted Attack Risk) - Combined risk score - Population (number of NHIs in fiber) - Percentile ranking Interactive Mode Navigation The interactive mode provides a 4-level drill-down interface for exploring fiber data: Screen 1: ","default_branch":null,"files":null,"tree":[],"storefront":"/r/labyrinthinesecurity","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/labyrinthinesecurity/silhouette/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}