Search
Microsoft Sentinel
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions. | Azure/ | 796 | — | ~703 | Automated safety check: Pass | MIT | today |
| 2 | KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools. | microsoft/ | 131 | — | ~6.2k | Automated safety check: Pass | MIT | 9 days ago |
| 3 | WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis. | jonathan-vella/ | 217 | — | ~2.1k | Automated safety check: Pass | MIT | today |
| 4 | A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format. | SCStelz/ | 249 | — | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 5 | Register and implement custom workflow triggers from an external Kibana plugin using @kbn/workflows-extensions. | elastic/ | 21k | — | ~3.5k | Automated safety check: Pass | Unknown | today |
| 6 | Audit Entra ID app registration and service principal security posture. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | yesterday |
| 7 | Monitor robot fleet telemetry via Azure IoT Operations, drift detection, Grafana dashboards, and Fabric analytics | microsoft/ | 126 | — | ~598 | Automated safety check: Pass | MIT | today |
| 8 | Automate Outlook tasks via Rube MCP (Composio): emails, calendar, contacts, folders, attachments. | davepoon/ | 3.6k | 7 repos | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 9 | Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Hunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE T1218, by analyzing endpoint process-creation logs for suspicious execution patterns of legitimate Windows system binaries… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. | mukul975/ | 34k | — | ~609 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics using KQL to fingerprint offensive Entra ID enumeration tools such as ROADtools, AADInternals, and… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Detect Golden Ticket attacks in Active Directory using Splunk and KQL queries against domain controller event logs, looking for Kerberos TGT anomalies such as mismatched encryption types, impossible… | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Search and filter Observability logs using ES|QL. An agent skill from aspectrr/deer. | aspectrr/ | 405 | — | ~1.3k | Automated safety check: Pass | MIT | 5 mo ago |
| 19 | 19.Siem Logging Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance. | ancoleman/ | 525 | — | ~3.4k | Automated safety check: Pass | MIT | 10 mo ago |
| 20 | Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 21 | Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. | briiirussell/ | 413 | — | ~2.6k | Automated safety check: Notes | MIT | 4 mo ago |
| 22 | Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis. | microsoft/ | 255 | 1 repo | ~2.1k | Automated safety check: Pass | MIT | today |
| 23 | Query Azure Application Insights telemetry data for command usage, extension activity, and performance metrics | forcedotcom/ | 1k | — | ~436 | Automated safety check: Pass | BSD-3-Clause | today |
| 24 | Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation… | mukul975/ | 34k | — | ~808 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 25 | A skill your agent uses when asked to create geographic maps, visualize attack origins on a world map, show location-based data, or display IP geolocation. | SCStelz/ | 249 | — | ~7.6k | Automated safety check: Pass | MIT | yesterday |
| 26 | Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. | microsoft/ | 255 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 27 | KQL language expertise for writing correct, efficient Kusto Query Language queries. | microsoft/ | 3.1k | — | ~4.7k | Automated safety check: Pass | MIT | today |
| 28 | A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. | SCStelz/ | 249 | — | ~13k | Automated safety check: Pass | MIT | yesterday |
| 29 | A skill your agent uses when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer. | SCStelz/ | 249 | — | ~5.7k | Automated safety check: Pass | MIT | yesterday |
| 30 | Turn a published threat-intelligence article into a tested threat-hunting campaign. | SCStelz/ | 249 | — | ~6.9k | Automated safety check: Pass | MIT | yesterday |
| 31 | ANALYSIS SKILL — Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL. | jonathan-vella/ | 217 | — | ~984 | Automated safety check: Pass | MIT | today |
| 32 | Build and query Kusto graphs from natural language. An agent skill from microsoft/GitHub-Copilot-for-Azure. | microsoft/ | 255 | — | ~4.8k | Automated safety check: Pass | MIT | today |
| 33 | Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. | microsoft/ | 255 | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 34 | Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization. | microsoft/ | 255 | — | ~4.8k | Automated safety check: Pass | MIT | today |
| 35 | Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk… | trilwu/ | 157 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 36 | Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules). | SCStelz/ | 249 | — | ~17k | Automated safety check: Pass | MIT | yesterday |
| 37 | 37.Defender Xdr Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 38 | Guidance for Microsoft Purview Records Management — declaring, managing, and disposing records across SharePoint, OneDrive, Exchange, and Teams. | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 39 | Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded… | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 40 | 40.Sentinel Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal. | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 41 | Guidance for the Microsoft unified security operations platform that brings Microsoft Sentinel, Microsoft Defender XDR, Security Copilot, Threat Intelligence, and Microsoft Security Exposure… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 42 | Expert knowledge for Content Safety in Foundry Control Plane development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security… | MicrosoftDocs/ | 776 | — | ~1.8k | Automated safety check: Pass | CC-BY-4.0 | 4 days ago |
| 43 | Expert knowledge for Azure External Attack Surface Management development including configuration. | MicrosoftDocs/ | 776 | — | ~935 | Automated safety check: Pass | CC-BY-4.0 | 4 days ago |
| 44 | Expert knowledge for Azure Sre Agent development including troubleshooting, best practices, decision making, architecture & design patterns, security, configuration, integrations & coding patterns… | MicrosoftDocs/ | 776 | — | ~2.7k | Automated safety check: Pass | CC-BY-4.0 | 4 days ago |