{"repo":"mvelazc0/BadZure","free":true,"listed":false,"github":"https://github.com/mvelazc0/BadZure","clone":"git clone https://github.com/mvelazc0/BadZure.git","description":"BadZure automates the deployment of intentionally misconfigured Entra ID tenants and Azure subscriptions, populating them with diverse entities and configurable, traversable attack paths.","language":"Python","stars":518,"topics":["attack-path","azure","entraid","purple-team"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"BadZure BadZure deploys intentionally misconfigured Entra ID tenants and Azure subscriptions so security teams can explore, exploit, and detect cloud attack paths in a real environment. It uses Terraform to populate a tenant with users, groups, applications, and Azure resources, then layers deliberate misconfigurations on top to produce complete privilege-escalation paths that span the identity and infrastructure planes. Every attack path begins at a compromised foothold and ends at a high-privilege target. BadZure provides the foothold credentials, so you start post-compromise and focus on the escalation itself. 📖 Full documentation: www.badzure.com Who it's for You might be one of these, or several: - 🗡️ Red teamers : rehearse Entra ID and Azure tradecraft in a safe, disposable tenant. - 🎯 Detection engineers & threat hunters : generate attack telemetry to build and validate detections. - 🟣 Purple teams : reproduce a specific technique end to end and watch it from both sides. - 🔬 Security researchers : explore cloud attack primitives and discover new ones. - 🎓 Trainers & CTF authors : run practical cloud security labs and capture the flag challenges. Attack paths BadZure provides two ways to author an attack path: atomic (one named technique template from a catalog of seven) and chained (an explicit graph built from lower-level primitives). A chained path can reproduce one catalog behavior or combine several into a custom route. The seven atomic templates span the ide","default_branch":null,"files":null,"tree":[],"storefront":"/r/mvelazc0","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mvelazc0/BadZure/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}