Exposure discovery Institution-led
ORADAZ
Beta command-line utility that dumps Azure configuration data through REST APIs to support security audits and manual exposure review.
By ANSSI · France
Primary sources connect this project to an EU public or research institution.
At a glance
Recorded facts- Response workflow
- Exposure discovery
- Developer or maintainer
- ANSSI
- Recorded country
- France
- Product model
- Open source
- Deployment
- Desktop/CLI
- Software license
- GPL-3.0
- Upstream status
- Experimental
- Evidence class
- Institution-led
What the sources establish
Origin notePublished by ANSSI, the French national cybersecurity agency, in its official project organization.
Reported capabilities
- Collects Azure configuration through REST APIs.
- Runs as an executable using an adjacent XML configuration file.
- Upstream explicitly marks the project beta.
Scope and limits
Upstream says beta and positions it for Azure security audits, not automated incident response or a general cloud posture platform.
Inspect the research evidence 3 source observations
identity / capabilities / deployment / maintenance
README labels ORADAZ beta and says it dumps Azure data through REST APIs for security audits; usage invokes oradaz.exe with an adjacent XML configuration.
Read sourcelicense
The upstream license is GNU General Public License version 3.
Read sourceorigin / country
ANSSI states its official repositories contain projects developed by the French national cybersecurity agency.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Scope exposure discovery, validate vulnerability findings, prioritize affected assets and verify remediation. Practical guidance with documented European tools.
From vulnerability finding to verified remediation