# Skry Security > Independent Microsoft Cloud offensive security practice. Attack path mapping, threat emulation, purple teaming, and security advisory. Based in Estonia. Tuomas Sillanaukee is an independent offensive security practitioner based in Estonia. Specialises in Microsoft Cloud offensive security: Azure attack path mapping, threat emulation, purple teaming, and detection engineering across Azure and Entra ID. Publishes technical research on Microsoft Cloud offensive security. ## Background Originally from Finland. Seven years in the Nordic tech sector in offensive security and consulting roles at WithSecure and CGI before going independent in 2026. Background covers both offensive and defensive work: started in a SOC, then years in offensive operations leading target-oriented threat emulations and dedicated purple team engagements while working directly alongside defenders. Before going independent: deep-dive penetration tests, complex environment audits, an embedded AppSec advisory role for major organisations, and on-call enterprise incident response. Sectors worked in: Heavy Industry and Manufacturing, Financial Services, Telecommunications, Government and Critical Infrastructure, and large-scale Enterprise IT. ## Services - **Azure Attack Path Mapping (Assumed Breach Cloud Diagnostic)**: Read-only assessment of your Microsoft Cloud environment. Maps how threat actors chain permissions from a realistic foothold to critical assets across Azure and Entra ID. Covers tier-0 compromise paths, workload identity exposure (Managed Identities, service principals), and external trust abuse. No active exploitation, no changes to your environment. - **Purple Teaming and Threat Emulation**: Real attack techniques executed against your live detection stack in coordination with your SOC. Two formats: Targeted Threat Emulation (scoped to highest-risk paths in a controlled client-owned environment) and Scenario-Based Purple Teaming (full attack chain from initial access to impact). KQL detection queries written from engagement data. - **Technical Security Advisory**: Offensive security expertise on retainer or per engagement. Cloud security architecture review, third-party findings review, regulatory preparation (NIS2, TIBER-EU). Available to organisations needing ongoing access to offensive security judgment, and to other red teams as an embedded Microsoft Cloud specialist. ## Technical Focus The domain is the Microsoft Cloud attack surface: Azure resource permissions, Entra ID identity relationships, and the trust chains between them. The work covers both sides of that surface. Attack path mapping and threat emulation on one side, detection coverage and validation on the other. Research and client work are grounded in how the environment actually behaves, tested against real Microsoft Cloud environments. ## Engagement Model Skry Security takes a small number of engagements per year. The typical client needs offensive security expertise applied to their Microsoft Cloud environment: understanding their actual attack surface, validating their detection coverage, or getting independent advisory on a specific risk or architecture decision. Available on a project or retainer basis. Also available as an embedded Microsoft Cloud specialist for other red teams on engagements requiring dedicated Azure and Entra ID depth. ## Location Based in Estonia. Works with clients across Europe and internationally. ## Contact - Email: contact@skrysecurity.com - LinkedIn: https://linkedin.com/in/tuomassillanaukee - GitHub: https://github.com/tuosec/ ## Key Pages - Homepage: https://skrysecurity.com/ - Azure Attack Path Mapping: https://skrysecurity.com/services/attack-path-mapping/ - Purple Teaming and Threat Emulation: https://skrysecurity.com/services/purple-teaming/ - Security Advisory: https://skrysecurity.com/services/advisory/ - About: https://skrysecurity.com/about/ - Insights (research): https://skrysecurity.com/insights/ - Full research library (LLM-optimised): https://skrysecurity.com/llms-full.txt - Post index (structured JSON): https://skrysecurity.com/insights.json ## Published Research - [The Nuances of targeting Azure App Services](https://skrysecurity.com/insights/app-service-key-vault-managed-identity/): The App Service attack path looks simple. The container mechanics underneath are not. This post covers the tradecraft behind it.