Search

By SCStelz

22 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…

SCStelz/security-investigator249—~3.8kAutomated safety check: PassMIT2 days ago
2

Weekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g.

SCStelz/security-investigator249—~3.7kAutomated safety check: PassMIT2 days ago
3

A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format.

SCStelz/security-investigator249—~3.4kAutomated safety check: PassMIT2 days ago
4

Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield…

SCStelz/security-investigator249—~17kAutomated safety check: PassMIT2 days ago
5

Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents.

SCStelz/security-investigator249—~21kAutomated safety check: PassMIT2 days ago
6

Audit Entra ID app registration and service principal security posture.

SCStelz/security-investigator249—~21kAutomated safety check: PassMIT2 days ago
7

A skill your agent uses when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins.

SCStelz/security-investigator249—~8.6kAutomated safety check: PassMIT2 days ago
8

Analyze data security events, sensitive information type (SIT) access, sensitivity label access, DLP matches, or Purview insider risk activity.

SCStelz/security-investigator249—~21kAutomated safety check: PassMIT2 days ago
9

Generate email threat protection reports and assess email security posture.

SCStelz/security-investigator249—~9.7kAutomated safety check: PassMIT2 days ago
10

A skill your agent uses when asked to generate a vulnerability and exposure management report, assess security posture, or review CVEs, security configurations, and attack paths.

SCStelz/security-investigator249—~15kAutomated safety check: PassMIT2 days ago
11

A skill your agent uses when asked to investigate a computer, device, endpoint, or machine for security issues, suspicious activity, malware, or compliance review.

SCStelz/security-investigator249—~15kAutomated safety check: WarnMIT2 days ago
12

A skill your agent uses when asked to create geographic maps, visualize attack origins on a world map, show location-based data, or display IP geolocation.

SCStelz/security-investigator249—~7.6kAutomated safety check: PassMIT2 days ago
13

A skill your agent uses when asked to analyze, investigate, or report on honeypot server security.

SCStelz/security-investigator249—~5.8kAutomated safety check: PassMIT2 days ago
14

Audit identity security posture across the organization. An agent skill from SCStelz/security-investigator.

SCStelz/security-investigator249—~14kAutomated safety check: PassMIT2 days ago
15

A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel.

SCStelz/security-investigator249—~13kAutomated safety check: PassMIT2 days ago
16

A skill your agent uses when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer.

SCStelz/security-investigator249—~5.7kAutomated safety check: PassMIT2 days ago
17

A skill your agent uses when asked to generate SVG data visualization dashboards from investigation data or skill reports.

SCStelz/security-investigator249—~5.7kAutomated safety check: PassMIT2 days ago
18

Turn a published threat-intelligence article into a tested threat-hunting campaign.

SCStelz/security-investigator249—~6.9kAutomated safety check: PassMIT2 days ago
19

Recommended starting point for new users and daily SOC operations.

SCStelz/security-investigator249—~25kAutomated safety check: PassMIT2 days ago
20

Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules).

SCStelz/security-investigator249—~17kAutomated safety check: PassMIT2 days ago
21

MITRE ATT&CK Coverage Report — YAML-driven PowerShell pipeline gathers analytic rule MITRE tags, custom detection techniques, SOC Optimization recommendations, and alert/incident operational data…

SCStelz/security-investigator249—~10kAutomated safety check: PassMIT2 days ago
22

Sentinel Ingestion Report — YAML-driven PowerShell pipeline gathers all data via az monitor/az rest/Graph API, writes a deterministic scratchpad, LLM renders the report.

SCStelz/security-investigator249—~16kAutomated safety check: PassMIT2 days ago