Cloud platform
Microsoft Sentinel agent skills for Claude Code, Codex and other agents.
- skills
- 43
- official
- 12
- Type
- Cloud platform
- Website
- azure.microsoft.com
- Official GitHub
- Azure
- Reviews
- See Microsoft Sentinel on Enlisted
Microsoft Sentinel skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
Official (12 skills)
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions. | Azure/ | 794 | — | ~703 | Automated safety check: Pass | MIT | 2 days ago |
| 2 | KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools. | microsoft/ | 131 | — | ~6.2k | Automated safety check: Pass | MIT | 6 days ago |
| 3 | Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. | microsoft/ | 255 | 1 repo | ~1.6k | Automated safety check: Pass | MIT | today |
| 4 | Monitor robot fleet telemetry via Azure IoT Operations, drift detection, Grafana dashboards, and Fabric analytics | microsoft/ | 122 | — | ~598 | Automated safety check: Pass | MIT | today |
| 5 | Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis. | microsoft/ | 255 | 1 repo | ~2.2k | Automated safety check: Pass | MIT | today |
| 6 | KQL language expertise for writing correct, efficient Kusto Query Language queries. | microsoft/ | 3.1k | — | ~4.7k | Automated safety check: Pass | MIT | yesterday |
| 7 | Build and query Kusto graphs from natural language. An agent skill from microsoft/GitHub-Copilot-for-Azure. | microsoft/ | 255 | — | ~4.8k | Automated safety check: Pass | MIT | today |
| 8 | Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. | microsoft/ | 255 | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 9 | Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization. | microsoft/ | 255 | — | ~4.8k | Automated safety check: Pass | MIT | today |
| 10 | Expert knowledge for Content Safety in Foundry Control Plane development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security… | MicrosoftDocs/ | 775 | — | ~1.8k | Automated safety check: Pass | CC-BY-4.0 | yesterday |
| 11 | Expert knowledge for Azure External Attack Surface Management development including configuration. | MicrosoftDocs/ | 775 | — | ~935 | Automated safety check: Pass | CC-BY-4.0 | yesterday |
| 12 | Expert knowledge for Azure Sre Agent development including troubleshooting, best practices, decision making, architecture & design patterns, security, configuration, integrations & coding patterns… | MicrosoftDocs/ | 775 | — | ~2.7k | Automated safety check: Pass | CC-BY-4.0 | yesterday |
Community
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 13 | WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis. | jonathan-vella/ | 217 | — | ~2.1k | Automated safety check: Pass | MIT | today |
| 14 | A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format. | SCStelz/ | 249 | — | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 15 | Audit Entra ID app registration and service principal security posture. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | yesterday |
| 16 | Automate Outlook tasks via Rube MCP (Composio): emails, calendar, contacts, folders, attachments. | davepoon/ | 3.6k | 7 repos | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 17 | Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Hunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE T1218, by analyzing endpoint process-creation logs for suspicious execution patterns of legitimate Windows system binaries… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 20 | Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. | mukul975/ | 34k | — | ~609 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 21 | Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 22 | Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 23 | Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics using KQL to fingerprint offensive Entra ID enumeration tools such as ROADtools, AADInternals, and… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 24 | Detect Golden Ticket attacks in Active Directory using Splunk and KQL queries against domain controller event logs, looking for Kerberos TGT anomalies such as mismatched encryption types, impossible… | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 25 | Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | 26.Siem Logging Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance. | ancoleman/ | 526 | — | ~3.4k | Automated safety check: Pass | MIT | 10 mo ago |
| 27 | Search and filter Observability logs using ES|QL. An agent skill from aspectrr/deer. | aspectrr/ | 405 | — | ~1.3k | Automated safety check: Pass | MIT | 5 mo ago |
| 28 | Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. | briiirussell/ | 412 | — | ~2.6k | Automated safety check: Notes | MIT | 4 mo ago |
| 30 | Query Azure Application Insights telemetry data for command usage, extension activity, and performance metrics | forcedotcom/ | 1k | — | ~436 | Automated safety check: Pass | BSD-3-Clause | today |
| 31 | Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation… | mukul975/ | 34k | — | ~808 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | A skill your agent uses when asked to create geographic maps, visualize attack origins on a world map, show location-based data, or display IP geolocation. | SCStelz/ | 249 | — | ~7.6k | Automated safety check: Pass | MIT | yesterday |
| 33 | A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. | SCStelz/ | 249 | — | ~13k | Automated safety check: Pass | MIT | yesterday |
| 34 | A skill your agent uses when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer. | SCStelz/ | 249 | — | ~5.7k | Automated safety check: Pass | MIT | yesterday |
| 35 | Turn a published threat-intelligence article into a tested threat-hunting campaign. | SCStelz/ | 249 | — | ~6.9k | Automated safety check: Pass | MIT | yesterday |
| 36 | ANALYSIS SKILL — Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL. | jonathan-vella/ | 217 | — | ~984 | Automated safety check: Pass | MIT | today |
| 37 | Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk… | trilwu/ | 156 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 38 | Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules). | SCStelz/ | 249 | — | ~17k | Automated safety check: Pass | MIT | yesterday |
| 39 | 39.Defender Xdr Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 40 | Guidance for Microsoft Purview Records Management — declaring, managing, and disposing records across SharePoint, OneDrive, Exchange, and Teams. | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 41 | Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded… | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 42 | 42.Sentinel Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal. | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 43 | Guidance for the Microsoft unified security operations platform that brings Microsoft Sentinel, Microsoft Defender XDR, Security Copilot, Threat Intelligence, and Microsoft Security Exposure… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
Questions, answered from the data.
What is the best Microsoft Sentinel skill?
Kql Validator (official) from Azure/azqr ranks first of the 43 Microsoft Sentinel skills listed here, with the highest score: its repository has 794 GitHub stars, its SKILL.md loads about 703 tokens and it passes the automated safety check with no findings. Next come Kql and Azure Diagnostics.
Is there an official Microsoft Sentinel skill?
12 of the 43 Microsoft Sentinel skills are official, published by the vendor's own GitHub organization: Kql Validator, Kql, Azure Diagnostics, Fleet Intelligence, Azure Kusto and 7 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.