Search
Microsoft Defender · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management. | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 2 | Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access. | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 3 | Detect abuse of service accounts by hunting for anomalous interactive logons, privilege escalation, and lateral movement using EDR/SIEM telemetry (CrowdStrike Falcon, Microsoft Defender, Splunk… | mukul975/ | 34k | — | ~904 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 4 | Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft… | mukul975/ | 34k | — | ~923 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 5 | Implement multi-cloud CSPM to detect cloud-native misconfigurations and vulnerabilities (IAM over-permissions, exposed storage, unencrypted data, missing network controls) using AWS Security Hub… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 6 | Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible-travel patterns, and credential-stuffing indicators using GuardDuty, Microsoft… | mukul975/ | 34k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 7 | Audit Azure Storage accounts for public blob containers, missing encryption, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 8 | Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 9 | Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databases, configuring… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall… | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 12 | 12.Azure Policy Guidance for Azure Policy — enforcing and auditing governance and security guardrails at scale across Azure with definitions, initiatives, assignments, and remediation tasks. | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 13 | A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. | SCStelz/ | 249 | — | ~13k | Automated safety check: Pass | MIT | 2 days ago |
| 14 | A skill your agent uses when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer. | SCStelz/ | 249 | — | ~5.7k | Automated safety check: Pass | MIT | 2 days ago |
| 15 | Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules). | SCStelz/ | 249 | — | ~17k | Automated safety check: Pass | MIT | 2 days ago |
| 16 | Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs… | trilwu/ | 157 | — | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 17 | 17.Azure Waf Guidance for Azure Web Application Firewall — deployed on Azure Front Door (global, edge-tier) or Azure Application Gateway (regional, integrated with backend pools). | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 18 | Guidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to… | vinayaklatthe/ | 175 | — | ~2.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 19 | Guidance for Microsoft Defender for Cloud Apps (MDA) — the CASB for SaaS discovery, app governance, session controls, and threat detection. | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 20 | Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP. | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 21 | Guidance for Microsoft Defender for Containers — Kubernetes and container security across AKS, Azure Arc-enabled Kubernetes, EKS, GKE, and OpenShift. | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 22 | Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation… | vinayaklatthe/ | 175 | — | ~2.3k | Automated safety check: Pass | MIT | 3 mo ago |
| 23 | Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors. | vinayaklatthe/ | 175 | — | ~2k | Automated safety check: Pass | MIT | 3 mo ago |
| 24 | Guidance for Microsoft Defender for IoT — agentless OT/ICS network detection and response for industrial environments, plus enterprise IoT (EIoT) protection integrated with Defender XDR. | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 25 | Guidance for Microsoft Defender for Storage — threat protection for Azure Storage accounts (Blob, Files, Data Lake Gen2). | vinayaklatthe/ | 175 | — | ~2k | Automated safety check: Pass | MIT | 3 mo ago |
| 26 | 26.Defender Xdr Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 27 | Guidance for Microsoft Entra Permissions Management (CIEM) — discovers, right-sizes, and monitors permissions across Microsoft Azure, AWS, and Google Cloud. | vinayaklatthe/ | 175 | — | ~1.7k | Automated safety check: Pass | MIT | 3 mo ago |
| 28 | Guidance for hardening macOS endpoints managed by Microsoft Intune — automated device enrollment via Apple Business Manager (ABM), platform single sign-on (PSSO) with Entra ID, FileVault disk… | vinayaklatthe/ | 175 | — | ~2.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 29 | Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded… | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 30 | 30.Sentinel Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal. | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 31 | Guidance for the Microsoft unified security operations platform that brings Microsoft Sentinel, Microsoft Defender XDR, Security Copilot, Threat Intelligence, and Microsoft Security Exposure… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 32 | Expert knowledge for Content Safety in Foundry Control Plane development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security… | MicrosoftDocs/ | 776 | — | ~1.8k | Automated safety check: Pass | CC-BY-4.0 | 5 days ago |
| 33 | Expert knowledge for Azure External Attack Surface Management development including configuration. | MicrosoftDocs/ | 776 | — | ~935 | Automated safety check: Pass | CC-BY-4.0 | 5 days ago |
| 34 | Expert knowledge for Azure Information Protection development including best practices, decision making, configuration, and deployment. | MicrosoftDocs/ | 776 | — | ~1.3k | Automated safety check: Pass | CC-BY-4.0 | 5 days ago |
| 35 | Expert knowledge for Azure Security development including best practices, decision making, security, configuration, integrations & coding patterns, and deployment. | MicrosoftDocs/ | 776 | — | ~3.4k | Automated safety check: Pass | CC-BY-4.0 | 5 days ago |