E-STO
Stormspotter
Microsoft red-team tool that builds a Neo4j attack graph of an Azure tenant's resources and Azure AD objects.
OVERVIEW
Stormspotter (github.com/Azure/Stormspotter) is a red-team tool released by Microsoft that collects Azure and Azure AD objects with a Python collector (`sscollector`, run via the Azure CLI session or a service principal) and renders them as an interactive attack graph on top of Neo4j and a web frontend.
Unlike identity-focused BloodHound collectors, Stormspotter leans toward the ARM/resource layer — VMs, storage accounts, key vaults, web apps, network security groups — and how they connect back to identities, so it is commonly used alongside AzureHound or ROADtools to combine the resource view with the identity view of the same tenant.
USE CASES
Practical use cases
- 01
Building a visual attack graph of an Azure subscription's VMs, storage accounts, key vaults, and web apps.
- 02
Identifying resources with public network exposure or overly permissive network security group rules.
- 03
Tracing how Azure AD identities connect to resource-level permissions (managed identities, RBAC assignments).
- 04
Combining Stormspotter's resource graph with an identity collector like AzureHound for a fuller tenant picture.
QUICK START
During Azure assessments to build a visual attack graph of a subscription or tenant's resources once read access is provisioned.
- Clone the repository and start the backend, frontend, and Neo4j with `docker-compose up`.
- Authenticate to the target tenant with `az login` using the client-provisioned assessment account.
- Run the collector — `python3 sscollector.pyz cli` (or `spn` mode with a service principal) — to gather resources and AD objects.
- Upload the collector's output through the web UI's database tab and explore the resulting attack graph.
az login && python3 sscollector.pyz cliBEFORE YOU RUN IT
What to check before running it
The collector reads broadly across Azure Resource Manager and Azure AD; agree with the client on expected Azure Activity Log and Entra ID sign-in volume before a full run.
The project has seen no significant updates in some time — review open issues before relying on it against current API versions, and test against a non-production tenant first.
The resulting attack graph is highly sensitive (it maps resource and identity relationships across the whole tenant) — store and share it under the engagement's data-handling rules.