Skip to content
View eshlomo1's full-sized avatar
💭
Just GIT
💭
Just GIT

Block or report eshlomo1

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
eshlomo1/README.md

Elli Shlomo

Microsoft Security MVP • Security Research • Cloud & AI Security Specialist • DFIR

I’m a security researcher who lives at the intersection of offensive operations, cloud abuse, identity abuse, and enterprise defence.
With a background in red-team tools, DFIR, threat hunting, cloud, and XDR (across M365, Azure, GCP, GWS), I enable defenders and testers to navigate the evolving threat terrain.


GitHub Stats

Stats Languages

Custom Language Focus

PowerShell Go Python KQL YAML JSON


OffSec AI / AI Security Research

I’m leading research into Offensive AI (OffSec AI) exploring how AI models, multi-agent systems, and orchestration frameworks can be exploited or hardened in real-world security contexts.

Current work includes:

  • AI Agent Exploitation: understanding prompt injection, memory poisoning, model context protocol (MCP) weaknesses, and autonomous sub-agent control hijacking.
  • AI-SOC Development: building frameworks that integrate LLM-based agents into SOC pipelines for automated triage, detection engineering, and red teaming.
  • PyRIT & MCP Experiments: leveraging Microsoft’s PyRIT and custom evaluation pipelines to measure resilience against jailbreaks and prompt chaining attacks.
  • AI-SPM (AI Security Posture Management): defining new detection layers for LLM-powered services inside Defender for Cloud and Sentinel.

Security by design is no longer optional, it’s survival.


Speaking, Writing & Community

  • Featured on my blog: Cyberdom.blog with deep dives into identity abuse, cloud hunting, AI red teaming, and OffSec AI.
  • Regularly present at Purple Hat events (attack/defend tracks) and community meet-ups.
  • Active on LinkedIn and X: follow for micro-insights on AI security, token abuse, and cloud IR.

Connect with Me


“Security isn’t just a stack of tools, it’s a mindset. Whether you’re hunting tokens, fuzzing OAuth, or tracing lateral cloud movement, stay curious, stay sceptical, and keep building.”

Pinned Loading

  1. CloudSec CloudSec Public

    Welcome to the Cloud Security Toolkit repository, your all-in-one destination for cutting-edge cloud security resources! Whether you're diving into offensive strategies, mastering threat hunting, o…

    PowerShell 37 10

  2. Microsoft-Sentinel-SecOps Microsoft-Sentinel-SecOps Public

    Microsoft Sentinel SOC Operations

    PowerShell 262 65

  3. Azure-AD-Incident-Response Azure-AD-Incident-Response Public

    Azure AD Incident Response

    26 3

  4. MS-Defender-4-xOPS MS-Defender-4-xOPS Public

    PowerShell 17 2