Cloud platform

Microsoft Sentinel agent skills for Claude Code, Codex and other agents.

Microsoft's cloud-native SIEM and SOAR for threat detection and response, queried with KQL.
skills
43
official
12
Type
Cloud platform
Website
azure.microsoft.com
Official GitHub
Azure
Reviews
See Microsoft Sentinel on Enlisted

Microsoft Sentinel skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Official (12 skills)

Official Microsoft Sentinel skills
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1
1.Kql ValidatorOfficial

Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.

Azure/azqr794—~703Automated safety check: PassMIT2 days ago
2
2.KqlOfficial

KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools.

microsoft/fabric-rti-mcp131—~6.2kAutomated safety check: PassMIT6 days ago
3

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage.

microsoft/GitHub-Copilot-for-Azure2551 repo~1.6kAutomated safety check: PassMITtoday
4

Monitor robot fleet telemetry via Azure IoT Operations, drift detection, Grafana dashboards, and Fabric analytics

microsoft/physical-ai-toolchain122—~598Automated safety check: PassMITtoday
5
5.Azure KustoOfficial

Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis.

microsoft/GitHub-Copilot-for-Azure2551 repo~2.2kAutomated safety check: PassMITtoday
6
6.KqlOfficial

KQL language expertise for writing correct, efficient Kusto Query Language queries.

microsoft/skills3.1k—~4.7kAutomated safety check: PassMITyesterday
7

Build and query Kusto graphs from natural language. An agent skill from microsoft/GitHub-Copilot-for-Azure.

microsoft/GitHub-Copilot-for-Azure255—~4.8kAutomated safety check: PassMITtoday
8

Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations.

microsoft/GitHub-Copilot-for-Azure255—~2.6kAutomated safety check: PassMITtoday
9

Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization.

microsoft/GitHub-Copilot-for-Azure255—~4.8kAutomated safety check: PassMITtoday
10

Expert knowledge for Content Safety in Foundry Control Plane development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security…

MicrosoftDocs/Agent-Skills775—~1.8kAutomated safety check: PassCC-BY-4.0yesterday
11

Expert knowledge for Azure External Attack Surface Management development including configuration.

MicrosoftDocs/Agent-Skills775—~935Automated safety check: PassCC-BY-4.0yesterday
12
12.Azure Sre AgentOfficial

Expert knowledge for Azure Sre Agent development including troubleshooting, best practices, decision making, architecture & design patterns, security, configuration, integrations & coding patterns…

MicrosoftDocs/Agent-Skills775—~2.7kAutomated safety check: PassCC-BY-4.0yesterday

Community

Community Microsoft Sentinel skills
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
13

WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.

jonathan-vella/apex217—~2.1kAutomated safety check: PassMITtoday
14

A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format.

SCStelz/security-investigator249—~3.4kAutomated safety check: PassMITyesterday
15

Audit Entra ID app registration and service principal security posture.

SCStelz/security-investigator249—~21kAutomated safety check: PassMITyesterday
16

Automate Outlook tasks via Rube MCP (Composio): emails, calendar, contacts, folders, attachments.

davepoon/buildwithclaude3.6k7 repos~1.9kAutomated safety check: PassMITyesterday
17

Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
18

Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
19

Hunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE T1218, by analyzing endpoint process-creation logs for suspicious execution patterns of legitimate Windows system binaries…

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
20

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.

mukul975/Anthropic-Cybersecurity-Skills34k—~609Automated safety check: PassApache-2.01 mo ago
21

Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.01 mo ago
22

Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
23

Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics using KQL to fingerprint offensive Entra ID enumeration tools such as ROADtools, AADInternals, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
24

Detect Golden Ticket attacks in Active Directory using Splunk and KQL queries against domain controller event logs, looking for Kerberos TGT anomalies such as mismatched encryption types, impossible…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.01 mo ago
25

Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
26

Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.

ancoleman/ai-design-components526—~3.4kAutomated safety check: PassMIT10 mo ago
27

Search and filter Observability logs using ES|QL. An agent skill from aspectrr/deer.

aspectrr/deer405—~1.3kAutomated safety check: PassMIT5 mo ago
28

Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks…

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
29

Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows.

briiirussell/cybersecurity-skills412—~2.6kAutomated safety check: NotesMIT4 mo ago
30

Query Azure Application Insights telemetry data for command usage, extension activity, and performance metrics

forcedotcom/salesforcedx-vscode1k—~436Automated safety check: PassBSD-3-Clausetoday
31

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation…

mukul975/Anthropic-Cybersecurity-Skills34k—~808Automated safety check: PassApache-2.01 mo ago
32

A skill your agent uses when asked to create geographic maps, visualize attack origins on a world map, show location-based data, or display IP geolocation.

SCStelz/security-investigator249—~7.6kAutomated safety check: PassMITyesterday
33

A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel.

SCStelz/security-investigator249—~13kAutomated safety check: PassMITyesterday
34

A skill your agent uses when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer.

SCStelz/security-investigator249—~5.7kAutomated safety check: PassMITyesterday
35

Turn a published threat-intelligence article into a tested threat-hunting campaign.

SCStelz/security-investigator249—~6.9kAutomated safety check: PassMITyesterday
36

ANALYSIS SKILL — Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL.

jonathan-vella/apex217—~984Automated safety check: PassMITtoday
37

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

trilwu/secskills156—~3.5kAutomated safety check: PassMIT1 mo ago
38

Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules).

SCStelz/security-investigator249—~17kAutomated safety check: PassMITyesterday
39

Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with…

vinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT3 mo ago
40

Guidance for Microsoft Purview Records Management — declaring, managing, and disposing records across SharePoint, OneDrive, Exchange, and Teams.

vinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT3 mo ago
41

Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded…

vinayaklatthe/microsoft-security-skills175—~1.8kAutomated safety check: PassMIT3 mo ago
42

Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.

vinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT3 mo ago
43

Guidance for the Microsoft unified security operations platform that brings Microsoft Sentinel, Microsoft Defender XDR, Security Copilot, Threat Intelligence, and Microsoft Security Exposure…

vinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT3 mo ago

Questions, answered from the data.

What is the best Microsoft Sentinel skill?

Kql Validator (official) from Azure/azqr ranks first of the 43 Microsoft Sentinel skills listed here, with the highest score: its repository has 794 GitHub stars, its SKILL.md loads about 703 tokens and it passes the automated safety check with no findings. Next come Kql and Azure Diagnostics.

Is there an official Microsoft Sentinel skill?

12 of the 43 Microsoft Sentinel skills are official, published by the vendor's own GitHub organization: Kql Validator, Kql, Azure Diagnostics, Fleet Intelligence, Azure Kusto and 7 more.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.