Search

Microsoft Sentinel

44 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1
1.Kql ValidatorOfficial

Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.

Azure/azqr796—~703Automated safety check: PassMITtoday
2
2.KqlOfficial

KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools.

microsoft/fabric-rti-mcp131—~6.2kAutomated safety check: PassMIT9 days ago
3

WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.

jonathan-vella/apex217—~2.1kAutomated safety check: PassMITtoday
4

A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format.

SCStelz/security-investigator249—~3.4kAutomated safety check: PassMITyesterday
5

Register and implement custom workflow triggers from an external Kibana plugin using @kbn/workflows-extensions.

elastic/kibana21k—~3.5kAutomated safety check: PassUnknowntoday
6

Audit Entra ID app registration and service principal security posture.

SCStelz/security-investigator249—~21kAutomated safety check: PassMITyesterday
7

Monitor robot fleet telemetry via Azure IoT Operations, drift detection, Grafana dashboards, and Fabric analytics

microsoft/physical-ai-toolchain126—~598Automated safety check: PassMITtoday
8

Automate Outlook tasks via Rube MCP (Composio): emails, calendar, contacts, folders, attachments.

davepoon/buildwithclaude3.6k7 repos~1.9kAutomated safety check: PassMITyesterday
9

Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
10

Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
11

Hunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE T1218, by analyzing endpoint process-creation logs for suspicious execution patterns of legitimate Windows system binaries…

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
12

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.

mukul975/Anthropic-Cybersecurity-Skills34k—~609Automated safety check: PassApache-2.01 mo ago
13

Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.01 mo ago
14

Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
15

Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics using KQL to fingerprint offensive Entra ID enumeration tools such as ROADtools, AADInternals, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
16

Detect Golden Ticket attacks in Active Directory using Splunk and KQL queries against domain controller event logs, looking for Kerberos TGT anomalies such as mismatched encryption types, impossible…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.01 mo ago
17

Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
18

Search and filter Observability logs using ES|QL. An agent skill from aspectrr/deer.

aspectrr/deer405—~1.3kAutomated safety check: PassMIT5 mo ago
19

Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance.

ancoleman/ai-design-components525—~3.4kAutomated safety check: PassMIT10 mo ago
20

Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks…

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
21

Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows.

briiirussell/cybersecurity-skills413—~2.6kAutomated safety check: NotesMIT4 mo ago
22
22.Azure KustoOfficial

Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis.

microsoft/GitHub-Copilot-for-Azure2551 repo~2.1kAutomated safety check: PassMITtoday
23

Query Azure Application Insights telemetry data for command usage, extension activity, and performance metrics

forcedotcom/salesforcedx-vscode1k—~436Automated safety check: PassBSD-3-Clausetoday
24

Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation…

mukul975/Anthropic-Cybersecurity-Skills34k—~808Automated safety check: PassApache-2.01 mo ago
25

A skill your agent uses when asked to create geographic maps, visualize attack origins on a world map, show location-based data, or display IP geolocation.

SCStelz/security-investigator249—~7.6kAutomated safety check: PassMITyesterday
26

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage.

microsoft/GitHub-Copilot-for-Azure255—~1.9kAutomated safety check: PassMITtoday
27
27.KqlOfficial

KQL language expertise for writing correct, efficient Kusto Query Language queries.

microsoft/skills3.1k—~4.7kAutomated safety check: PassMITtoday
28

A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel.

SCStelz/security-investigator249—~13kAutomated safety check: PassMITyesterday
29

A skill your agent uses when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer.

SCStelz/security-investigator249—~5.7kAutomated safety check: PassMITyesterday
30

Turn a published threat-intelligence article into a tested threat-hunting campaign.

SCStelz/security-investigator249—~6.9kAutomated safety check: PassMITyesterday
31

ANALYSIS SKILL — Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL.

jonathan-vella/apex217—~984Automated safety check: PassMITtoday
32

Build and query Kusto graphs from natural language. An agent skill from microsoft/GitHub-Copilot-for-Azure.

microsoft/GitHub-Copilot-for-Azure255—~4.8kAutomated safety check: PassMITtoday
33
33.Azure Kusto IrqlOfficial

Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations.

microsoft/GitHub-Copilot-for-Azure255—~2.6kAutomated safety check: PassMITtoday
34

Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization.

microsoft/GitHub-Copilot-for-Azure255—~4.8kAutomated safety check: PassMITtoday
35

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

trilwu/secskills157—~3.5kAutomated safety check: PassMIT1 mo ago
36

Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules).

SCStelz/security-investigator249—~17kAutomated safety check: PassMITyesterday
37

Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with…

vinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT3 mo ago
38

Guidance for Microsoft Purview Records Management — declaring, managing, and disposing records across SharePoint, OneDrive, Exchange, and Teams.

vinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT3 mo ago
39

Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded…

vinayaklatthe/microsoft-security-skills175—~1.8kAutomated safety check: PassMIT3 mo ago
40

Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.

vinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT3 mo ago
41

Guidance for the Microsoft unified security operations platform that brings Microsoft Sentinel, Microsoft Defender XDR, Security Copilot, Threat Intelligence, and Microsoft Security Exposure…

vinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT3 mo ago
42

Expert knowledge for Content Safety in Foundry Control Plane development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security…

MicrosoftDocs/Agent-Skills776—~1.8kAutomated safety check: PassCC-BY-4.04 days ago
43

Expert knowledge for Azure External Attack Surface Management development including configuration.

MicrosoftDocs/Agent-Skills776—~935Automated safety check: PassCC-BY-4.04 days ago
44
44.Azure Sre AgentOfficial

Expert knowledge for Azure Sre Agent development including troubleshooting, best practices, decision making, architecture & design patterns, security, configuration, integrations & coding patterns…

MicrosoftDocs/Agent-Skills776—~2.7kAutomated safety check: PassCC-BY-4.04 days ago