Search
Microsoft Sentinel · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis. | jonathan-vella/ | 217 | — | ~2.1k | Automated safety check: Pass | MIT | yesterday |
| 2 | Monitor robot fleet telemetry via Azure IoT Operations, drift detection, Grafana dashboards, and Fabric analytics | microsoft/ | 126 | — | ~598 | Automated safety check: Pass | MIT | 2 days ago |
| 3 | Hunts for LOLBins (Living Off the Land Binaries) abuse, mapped to MITRE T1218, by analyzing endpoint process-creation logs for suspicious execution patterns of legitimate Windows system binaries… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 4 | Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 5 | Search and filter Observability logs using ES|QL. An agent skill from aspectrr/deer. | aspectrr/ | 405 | — | ~1.3k | Automated safety check: Pass | MIT | 5 mo ago |
| 6 | Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. | briiirussell/ | 413 | — | ~2.6k | Automated safety check: Notes | MIT | 4 mo ago |
| 7 | Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. | microsoft/ | 255 | — | ~1.9k | Automated safety check: Pass | MIT | yesterday |
| 8 | Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk… | trilwu/ | 157 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 9 | Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules). | SCStelz/ | 249 | — | ~17k | Automated safety check: Pass | MIT | 3 days ago |
| 10 | 10.Sentinel Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal. | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 11 | Expert knowledge for Azure Sre Agent development including troubleshooting, best practices, decision making, architecture & design patterns, security, configuration, integrations & coding patterns… | MicrosoftDocs/ | 776 | — | ~2.7k | Automated safety check: Pass | CC-BY-4.0 | 5 days ago |