Search
Microsoft Sentinel · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions. | Azure/ | 796 | — | ~703 | Automated safety check: Pass | MIT | 2 days ago |
| 2 | WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis. | jonathan-vella/ | 217 | — | ~2.1k | Automated safety check: Pass | MIT | today |
| 3 | A skill your agent uses when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format. | SCStelz/ | 249 | — | ~3.4k | Automated safety check: Pass | MIT | 2 days ago |
| 4 | Register and implement custom workflow triggers from an external Kibana plugin using @kbn/workflows-extensions. | elastic/ | 21k | — | ~3.5k | Automated safety check: Pass | Unknown | today |
| 5 | Audit Entra ID app registration and service principal security posture. | SCStelz/ | 249 | — | ~21k | Automated safety check: Pass | MIT | 2 days ago |
| 6 | Monitor robot fleet telemetry via Azure IoT Operations, drift detection, Grafana dashboards, and Fabric analytics | microsoft/ | 126 | — | ~598 | Automated safety check: Pass | MIT | yesterday |
| 7 | Automate Outlook tasks via Rube MCP (Composio): emails, calendar, contacts, folders, attachments. | davepoon/ | 3.6k | 7 repos | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 8 | Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 9 | Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. | mukul975/ | 34k | — | ~609 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Deploy Microsoft Sentinel as a cloud-native SIEM/SOAR by configuring multi-cloud data connectors (AWS, Azure, GCP), writing KQL detection and hunting queries, and building automated Logic Apps… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Hunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics using KQL to fingerprint offensive Entra ID enumeration tools such as ROADtools, AADInternals, and… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Detect Golden Ticket attacks in Active Directory using Splunk and KQL queries against domain controller event logs, looking for Kerberos TGT anomalies such as mismatched encryption types, impossible… | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Search and filter Observability logs using ES|QL. An agent skill from aspectrr/deer. | aspectrr/ | 405 | — | ~1.3k | Automated safety check: Pass | MIT | 5 mo ago |
| 16 | 16.Siem Logging Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance. | ancoleman/ | 525 | — | ~3.4k | Automated safety check: Pass | MIT | 10 mo ago |
| 17 | Identify command-and-control beaconing patterns in network traffic by applying statistical frequency analysis, jitter calculation, and coefficient of variation scoring to detect periodic callbacks… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation… | mukul975/ | 34k | — | ~808 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | A skill your agent uses when asked to create geographic maps, visualize attack origins on a world map, show location-based data, or display IP geolocation. | SCStelz/ | 249 | — | ~7.6k | Automated safety check: Pass | MIT | 2 days ago |
| 20 | Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. | microsoft/ | 255 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 21 | A skill your agent uses when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. | SCStelz/ | 249 | — | ~13k | Automated safety check: Pass | MIT | 2 days ago |
| 22 | A skill your agent uses when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer. | SCStelz/ | 249 | — | ~5.7k | Automated safety check: Pass | MIT | 2 days ago |
| 23 | Turn a published threat-intelligence article into a tested threat-hunting campaign. | SCStelz/ | 249 | — | ~6.9k | Automated safety check: Pass | MIT | 2 days ago |
| 24 | ANALYSIS SKILL — Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL. | jonathan-vella/ | 217 | — | ~984 | Automated safety check: Pass | MIT | yesterday |
| 25 | Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. | microsoft/ | 255 | — | ~2.6k | Automated safety check: Pass | MIT | yesterday |
| 26 | Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules). | SCStelz/ | 249 | — | ~17k | Automated safety check: Pass | MIT | 2 days ago |
| 27 | 27.Defender Xdr Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 28 | Guidance for Microsoft Security Copilot - the generative-AI security platform that helps analysts investigate, hunt, summarise, and respond using natural language, plugins, promptbooks, and embedded… | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 29 | 29.Sentinel Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal. | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 30 | Guidance for the Microsoft unified security operations platform that brings Microsoft Sentinel, Microsoft Defender XDR, Security Copilot, Threat Intelligence, and Microsoft Security Exposure… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 31 | Expert knowledge for Content Safety in Foundry Control Plane development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security… | MicrosoftDocs/ | 776 | — | ~1.8k | Automated safety check: Pass | CC-BY-4.0 | 5 days ago |
| 32 | Expert knowledge for Azure External Attack Surface Management development including configuration. | MicrosoftDocs/ | 776 | — | ~935 | Automated safety check: Pass | CC-BY-4.0 | 5 days ago |