Search
By SCStelz
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy… | SCStelz/ | 249 | — | ~3.8k | Automated safety check: Pass | MIT | 2 days ago |
| 2 | Weekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g. | SCStelz/ | 249 | — | ~3.7k | Automated safety check: Pass | MIT | 2 days ago |
| 3 | A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format. | SCStelz/ | 249 | — | ~3.4k | Automated safety check: Pass | MIT | 2 days ago |
| 4 | Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield… | SCStelz/ | 249 | — | ~17k | Automated safety check: Pass | MIT | 2 days ago |
| 5 | Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | 2 days ago |
| 6 | Audit Entra ID app registration and service principal security posture. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | 2 days ago |
| 7 | A skill your agent uses when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins. | SCStelz/ | 249 | — | ~8.6k | Automated safety check: Pass | MIT | 2 days ago |
| 8 | Analyze data security events, sensitive information type (SIT) access, sensitivity label access, DLP matches, or Purview insider risk activity. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | 2 days ago |
| 9 | Generate email threat protection reports and assess email security posture. | SCStelz/ | 249 | — | ~9.7k | Automated safety check: Pass | MIT | 2 days ago |
| 10 | A skill your agent uses when asked to generate a vulnerability and exposure management report, assess security posture, or review CVEs, security configurations, and attack paths. | SCStelz/ | 249 | — | ~15k | Automated safety check: Pass | MIT | 2 days ago |
| 11 | A skill your agent uses when asked to investigate a computer, device, endpoint, or machine for security issues, suspicious activity, malware, or compliance review. | SCStelz/ | 249 | — | ~15k | Automated safety check: Warn | MIT | 2 days ago |
| 12 | A skill your agent uses when asked to create geographic maps, visualize attack origins on a world map, show location-based data, or display IP geolocation. | SCStelz/ | 249 | — | ~7.6k | Automated safety check: Pass | MIT | 2 days ago |
| 13 | A skill your agent uses when asked to analyze, investigate, or report on honeypot server security. | SCStelz/ | 249 | — | ~5.8k | Automated safety check: Pass | MIT | 2 days ago |
| 14 | Audit identity security posture across the organization. An agent skill from SCStelz/security-investigator. | SCStelz/ | 249 | — | ~14k | Automated safety check: Pass | MIT | 2 days ago |
| 15 | A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. | SCStelz/ | 249 | — | ~13k | Automated safety check: Pass | MIT | 2 days ago |
| 16 | A skill your agent uses when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer. | SCStelz/ | 249 | — | ~5.7k | Automated safety check: Pass | MIT | 2 days ago |
| 17 | A skill your agent uses when asked to generate SVG data visualization dashboards from investigation data or skill reports. | SCStelz/ | 249 | — | ~5.7k | Automated safety check: Pass | MIT | 2 days ago |
| 18 | Turn a published threat-intelligence article into a tested threat-hunting campaign. | SCStelz/ | 249 | — | ~6.9k | Automated safety check: Pass | MIT | 2 days ago |
| 19 | 19.Threat Pulse Recommended starting point for new users and daily SOC operations. | SCStelz/ | 249 | — | ~25k | Automated safety check: Pass | MIT | 2 days ago |
| 20 | Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules). | SCStelz/ | 249 | — | ~17k | Automated safety check: Pass | MIT | 2 days ago |
| 21 | MITRE ATT&CK Coverage Report — YAML-driven PowerShell pipeline gathers analytic rule MITRE tags, custom detection techniques, SOC Optimization recommendations, and alert/incident operational data… | SCStelz/ | 249 | — | ~10k | Automated safety check: Pass | MIT | 2 days ago |
| 22 | Sentinel Ingestion Report — YAML-driven PowerShell pipeline gathers all data via az monitor/az rest/Graph API, writes a deterministic scratchpad, LLM renders the report. | SCStelz/ | 249 | — | ~16k | Automated safety check: Pass | MIT | 2 days ago |