Kql Validator
Azure/azqr
Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.
Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql-graph -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql-graph --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph .claude/skills/azure-kusto-irql-graph && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azure-kusto-irql-graph" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph into .claude/skills/azure-kusto-irql-graph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql-graph", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graphType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql-graph -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql-graph --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph .agents/skills/azure-kusto-irql-graph && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azure-kusto-irql-graph" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph into .agents/skills/azure-kusto-irql-graph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql-graph", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql-graph -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql-graph --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph .cursor/skills/azure-kusto-irql-graph && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azure-kusto-irql-graph" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph into .cursor/skills/azure-kusto-irql-graph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql-graph", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft/GitHub-Copilot-for-Azure.git --path plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql-graph -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql-graph --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph .gemini/skills/azure-kusto-irql-graph && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azure-kusto-irql-graph" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph into .gemini/skills/azure-kusto-irql-graph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql-graph", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql-graphInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql-graph -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph .github/skills/azure-kusto-irql-graph && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azure-kusto-irql-graph" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph into .github/skills/azure-kusto-irql-graph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql-graph", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql-graph -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql-graph --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph .opencode/skills/azure-kusto-irql-graph && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azure-kusto-irql-graph" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph into .opencode/skills/azure-kusto-irql-graph/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql-graph", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azure-kusto-irql-graphApply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization.
Azure Kusto Irql Graph is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization. Generates LiftToGraph mappings and composes GraphRenderView, GraphFoldByProperty, ExtractNode, EnrichNode, and EnrichGraph calls. Accepts a supplied query or limited basic natural-language source request; it is not a general natural-language-to-KQL/IRQL skill. WHEN: LiftToGraph, GraphRenderView, GraphFoldByProperty, IRQL graph enrichment, graph mapping for existing query results, icon-decorated graph, fold graph nodes. Use…
Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/DEPLOY_IRQL_FUNCTIONS.md`, `references/EXAMPLES.md` and `references/KUSTO_EXPLORER_LAUNCH.md`).
It works with Microsoft Azure and Microsoft Sentinel. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ce94fce. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are kql).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
raw.githubusercontent.comkc7001.eastus.kusto.windows.netFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azure Kusto Irql Graph loads about 4.8k tokens when it runs, and up to ~9.2k if it reads all its reference files. Until then it costs about 169 tokens; SKILL.md has 1,488 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from microsoft/GitHub-Copilot-for-Azure at commit ce94fce, republished under its MIT licence (© microsoft). 1,488 words, ~4,781 tokens.
.claude/skills/azure-kusto-irql-graph/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Apply the IRQL graph function family to tabular results. Given a KQL or IRQL query and the user's graph description, generate a Lift_To_Graph mapping and compose only the stored graph functions needed to visualize, fold, extract, or enrich the graph in Kusto Explorer. The source query does not need to use IRQL.
| Request | Use |
|---|---|
| Turn supplied KQL/IRQL rows into an icon-decorated visual graph | This skill: Lift_To_Graph + Graph_Render_View |
Fold nodes or apply Extract_Node_*, Enrich_Node_*, or Enrich_Graph_* | This skill |
Use make-graph, graph-match, shortest paths, connected components, graph models, or snapshots | azure-kusto-graph |
| Author a non-trivial KQL/IRQL investigation from natural language | A Kusto or IRQL query-generation skill, then this skill |
If a request mixes visualization and native graph analysis, use this skill for the lift/render portion and azure-kusto-graph for operator semantics. Do not replace graph-lift functions with a hand-built edges-first graph unless the user asks for native graph operators.
Get_* selector with obvious columns and simple filters. State the assumed source, and do not invent joins, schema, or investigation logic.Use this skill when the user:
Lift_To_Graph, Graph_Render_View, or Graph_Fold_By_PropertyExtract_Node_*, Enrich_Node_*, or Enrich_Graph_*Do not activate this skill solely for graph-match, graph paths/components, persistent graphs, or generic make-graph construction; those belong to azure-kusto-graph.
Not a natural-language-to-KQL/IRQL converter. The input should generally be a working KQL or IRQL query whose results need graph visualization. Basic NL source requests work only for trivial single-table/selector cases. For general NL-to-KQL or NL-to-IRQL, use a dedicated query-generation skill (available separately).
https://kc7001.eastus.kusto.windows.netValdyTimes, JoJosHospital (graph functions pre-deployed)kusto_query (via Azure MCP Server)Lift_To_Graph and Graph_Render_View are stored functions, not built-in Kusto operators. Before generating or running a lift pipeline against a target database, check what is deployed:
.show functions
| where Name in~ ("Lift_To_Graph", "Graph_Render_View", "Graph_Fold_By_Property")
| project NameLift_To_Graph and Graph_Render_View are required.Graph_Fold_By_Property is required only when folding is requested.Extract_Node_*, Enrich_Node_*, or Enrich_Graph_* function before using it; omit optional enrichment when unavailable unless the user wants it deployed..create-or-alter function definitions in references/DEPLOY_IRQL_FUNCTIONS.md. Run the relevant .create-or-alter block, then rerun the preflight check to confirm.references/DEPLOY_IRQL_FUNCTIONS.md for manual deployment.Lift_To_Graph(T, mappingJson)Transforms any tabular KQL result into a unified node + edge table.
Input: Any table T + a JSON mapping string.
Output: Rows with EntityType = "node" or "edge", ready for make-graph.
Graph_Render_View(T)Takes Lift_To_Graph output, splits nodes/edges, and calls make-graph to open Kusto Explorer's graph window.
Graph_Fold_By_Property(T, NodeType, PropertyName)Collapses nodes of a given type sharing a property value into a single node. Rewires edges automatically.
These are additional stored functions that must already be deployed on the target database. They are not bundled in references/DEPLOY_IRQL_FUNCTIONS.md. Use .show functions to verify availability before including in a pipeline.
| Function | Operation | Key Property |
|---|---|---|
Extract_Node_Email_Sender_Domain(T, displayName) | Adds Domain to node props | EmailSender |
Extract_Node_Employee_Firstname(T, displayName) | Adds Firstname to node props | Name |
Extract_Node_Event_Network_Domain(T, displayName) | Adds DomainName to node props | Url |
Enrich_Node_Ip_Employee(T, displayName) | Adds employee info to IP nodes | ClientIp |
Enrich_Node_Username_Employee(T, displayName) | Adds employee info to user nodes | Username |
Enrich_Node_Event_Authentication_Username(T, displayName) | Adds auth context | Username |
Enrich_Node_Ip_Domain(T, displayName) | Adds DNS domains | ClientIp |
Enrich_Node_Ip_Event_NetworkOutbound(T, displayName) | Adds outbound events | ClientIp |
Enrich_Graph_Ip_Employee(T, mappingJson) | Expands graph with employee nodes | ClientIp |
Enrich_Graph_Username_Employee(T, mappingJson) | Expands graph with employee nodes | Username |
Enrich_Graph_Event_Authentication_Username(T, mappingJson) | Expands with auth nodes | Username |
The JSON mapping has two arrays: node_types and edges.
node_types[]| Field | Required | Description |
|---|---|---|
type | Yes | Node type label (e.g. "User", "Host", "IP") |
id | Yes | Prefix for node ID; usually same as type |
key | Yes | Column name whose value becomes the node's identity |
props | Yes | Array of columns to carry as node properties |
defaults | No | Object of fallback values for null/empty properties |
defIcon | No | Default icon URL for this node type |
displayName | No | Column to use for display label (defaults to id) |
color | No | Column to source color from |
size | No | Column to source size from |
edges[]| Field | Required | Description |
|---|---|---|
type | Yes | Edge type label (e.g. "AuthenticatesTo", "SentEmail") |
source | Yes | {"id": "<prefix>", "type": "<NodeType>"} |
target | Yes | {"id": "<prefix>", "type": "<NodeType>"} |
props | No | Array of columns to carry as edge properties |
displayName | No | Column for edge label |
color | No | Column for edge color |
Use icons from https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/:
Public-IP-Addresses-(Classic).svgVirtual-Machine.svgUsers.svgMailbox.svg (or azure-cds/command-1070-Mail.svg)App-Services.svgStorage-Accounts.svgActivity-Log.svgDNS-Zones.svgGiven the supplied query columns and the user's graph description, generate the mapping JSON by:
node_typeedge| Entity | Key Column | Available Props |
|---|---|---|
| User | Username | Username, Name, Role, Email |
| Host | Hostname | Hostname |
| IP | ClientIp | ClientIp |
| Email Message | Subject | EnvTime, Subject, Verdict, Url |
| Sender | EmailSender | EmailSender, Domain |
| Recipient | EmailRecipient | EmailRecipient |
| Process | ProcessName | EnvTime, ProcessName, ProcessCommandLine, ProcessHash |
| File | Filename | EnvTime, Filename, Path, Sha256 |
| Domain | DomainName | DomainName |
| Auth Event | (synthetic ID) | EnvTime, UserAgent, Result, Description |
Lift_To_Graph(mapping) to create graph entities.Extract_Node_*, Enrich_Node_*, or Enrich_Graph_* only when requested and compatible with the mapped keys.Graph_Fold_By_Property() only when grouping/collapse is requested.Graph_Render_View().// 1. Preserve the supplied KQL or IRQL query
<input query>
// 2. Lift to graph
| invoke Lift_To_Graph(<mapping_json>)
// 3. Optionally extract or enrich graph entities
| invoke <Extract_Node_* | Enrich_Node_* | Enrich_Graph_*>()
// 4. Optionally fold nodes when requested
| invoke Graph_Fold_By_Property("<NodeType>", "<PropertyName>")
// 5. Render
| invoke Graph_Render_View()For additional prompts and worked examples, see references/EXAMPLES.md.
Input query: Get_Event_Authentication_All | where Result == "Failed Login" | take 200
Graph request: "Show IPs, authentication events, users, and hosts; fold events by result."
let auth_mapping = '{"node_types":[{"type":"SrcIp","id":"SrcIp","key":"ClientIp","props":["ClientIp"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/Public-IP-Addresses-(Classic).svg"},{"type":"Host","id":"Host","key":"Hostname","props":["Hostname"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/Virtual-Machine.svg"},{"type":"User","id":"User","key":"Username","props":["Username"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/Users.svg"},{"type":"AuthEvent","id":"AuthEvent","key":"AuthEventId","props":["AuthEventId","EnvTime","UserAgent","Result","Description"],"defaults":{"Result":"unknown"},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/Activity-Log.svg"}],"edges":[{"type":"RequestsAuth","source":{"id":"SrcIp","type":"SrcIp"},"target":{"id":"AuthEvent","type":"AuthEvent"},"props":["EnvTime"]},{"type":"TargetsUser","source":{"id":"AuthEvent","type":"AuthEvent"},"target":{"id":"User","type":"User"},"props":["EnvTime"]},{"type":"AgainstHost","source":{"id":"AuthEvent","type":"AuthEvent"},"target":{"id":"Host","type":"Host"},"props":["EnvTime"]}]}';
Get_Event_Authentication_All
| extend AuthEventId = strcat(Username, "_", Hostname, "_", EnvTime)
| where Result == "Failed Login"
| take 200
| invoke Lift_To_Graph(auth_mapping)
| invoke Graph_Fold_By_Property("AuthEvent", "Result")
| invoke Graph_Render_View()Input query: Get_Email_All | take 400
Graph request: "Visualize sender-to-message-to-recipient flow and fold messages by verdict."
let mail_mapping = '{"node_types":[{"type":"EmailMessage","id":"Message","key":"Subject","props":["EnvTime","Subject","Verdict"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/Media-File.svg"},{"type":"Sender","id":"Email","key":"EmailSender","props":["EmailSender"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-cds/command-1070-Mail.svg"},{"type":"Recipient","id":"Email","key":"EmailRecipient","props":["EmailRecipient"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-cds/command-1070-Mail.svg"}],"edges":[{"type":"SentBy","source":{"id":"Message","type":"EmailMessage"},"target":{"id":"Email","type":"Sender"},"props":["EnvTime","Verdict"]},{"type":"DeliveredTo","source":{"id":"Message","type":"EmailMessage"},"target":{"id":"Email","type":"Recipient"},"props":["EnvTime","Verdict"]}]}';
Get_Email_All
| take 400
| invoke Lift_To_Graph(mail_mapping)
| invoke Graph_Fold_By_Property("EmailMessage", "Verdict")
| invoke Graph_Render_View()Basic source request: "Use outbound network events for these suspicious domains and graph IP-to-domain connections enriched with employee names."
This is the limited fallback: one known selector, one extractor, and one direct filter.
let suspicious_domain_mapping = '{"node_types":[{"type":"IP","id":"IP","key":"ClientIp","props":["ClientIp"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/Public-IP-Addresses-(Classic).svg"},{"type":"Domain","id":"Domain","key":"DomainName","props":["DomainName"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/DNS-Zones.svg"}],"edges":[{"type":"ConnectsTo","source":{"id":"IP","type":"IP"},"target":{"id":"Domain","type":"Domain"},"props":["EnvTime"]}]}';
Get_Event_NetworkOutbound
| invoke Extract_Event_Network_Domain()
| where DomainName has_any ("raisinkanes.com", "nothing-to-see-here.net", "totally-legit-domain.com")
| invoke Lift_To_Graph(suspicious_domain_mapping)
| invoke Enrich_Node_Ip_Employee("Name")
| invoke Graph_Fold_By_Property("Domain", "DomainName")
| invoke Graph_Render_View()Input query: Get_Event_Process_All | where ProcessCommandLine has "powershell" | take 300
Graph request: "Visualize process, parent process, host, and user relationships."
let proc_mapping = '{"node_types":[{"type":"Process","id":"Proc","key":"ProcessName","props":["ProcessName","ProcessCommandLine","ProcessHash"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/App-Services.svg"},{"type":"ParentProcess","id":"Proc","key":"ParentProcessName","props":["ParentProcessName","ParentProcessHash"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/App-Services.svg"},{"type":"Host","id":"Host","key":"Hostname","props":["Hostname"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/Virtual-Machine.svg"},{"type":"User","id":"User","key":"Username","props":["Username"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/Users.svg"}],"edges":[{"type":"SpawnedBy","source":{"id":"Proc","type":"Process"},"target":{"id":"Proc","type":"ParentProcess"},"props":["EnvTime"]},{"type":"RanOn","source":{"id":"Proc","type":"Process"},"target":{"id":"Host","type":"Host"},"props":["EnvTime"]},{"type":"ExecutedBy","source":{"id":"Proc","type":"Process"},"target":{"id":"User","type":"User"},"props":["EnvTime"]}]}';
Get_Event_Process_All
| where ProcessCommandLine has "powershell"
| take 300
| invoke Lift_To_Graph(proc_mapping)
| invoke Graph_Render_View()When the user supplies a query and describes the graph:
Lift_To_Graph()Graph_Render_View() at the endGraph_Fold_By_Property()Output the complete KQL -- the supplied query plus mapping JSON inline as a string let binding -- after the required-function preflight passes. Clearly mark unverified function dependencies when the target database cannot be checked.
Optional convenience feature. The default workflow is to output the KQL in chat and let the user copy it into Kusto Explorer or the VS Code Kusto extension manually. Auto-launch is opt-in only.
Always output the complete KQL query in the chat response with Step 1 (connect) and Step 2 (query) clearly labeled:
// Step 1: Connect to your cluster (skip if already connected)
// Example: uncomment to connect to the KC7 training cluster
// #connect cluster('kc7001.eastus.kusto.windows.net').database('ValdyTimes')
// Or replace with your own cluster:
// #connect cluster('<YOUR_CLUSTER>').database('<YOUR_DATABASE>')
// Step 2: Run the query below
<KQL_QUERY>If the user asks to save or open in Kusto Explorer, follow the procedure in references/KUSTO_EXPLORER_LAUNCH.md. Key rules:
ask_user to confirm before writing files or launching executablesSet-Content/Add-Content.kql file and suggest the VS Code Kusto extension or ADX Web Explorer© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph of microsoft/GitHub-Copilot-for-Azure.
Open the folder on GitHubat commit ce94fce
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.
Azure Kusto Irql Graph next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azure Kusto Irql Graph this skillmicrosoft/GitHub-Copilot-for-Azure | 255 | — | ~4.8k | Automated safety check: Pass | MIT | |
| Kql ValidatorAzure/azqr | 795 | — | ~703 | Automated safety check: Pass | MIT | |
| Kqlmicrosoft/fabric-rti-mcp | 131 | — | ~6.2k | Automated safety check: Pass | MIT | |
| Apex Azure Diagnosticsjonathan-vella/apex | 217 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Fleet Intelligencemicrosoft/physical-ai-toolchain | 123 | — | ~598 | Automated safety check: Pass | MIT | |
| Deploying Cloud Deception With Decoy Resourcesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 |
Azure/azqr
Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.
microsoft/fabric-rti-mcp
KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools.
jonathan-vella/apex
WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.
microsoft/physical-ai-toolchain
Monitor robot fleet telemetry via Azure IoT Operations, drift detection, Grafana dashboards, and Fabric analytics
mukul975/Anthropic-Cybersecurity-Skills
Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…
mukul975/Anthropic-Cybersecurity-Skills
Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…
microsoft/GitHub-Copilot-for-Azure
Discovers available Azure OpenAI model capacity across regions and projects.
microsoft/GitHub-Copilot-for-Azure
Unified Azure OpenAI model deployment skill with intelligent intent-based routing.
microsoft/GitHub-Copilot-for-Azure
Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.
microsoft/GitHub-Copilot-for-Azure
Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.
microsoft/GitHub-Copilot-for-Azure
Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…
microsoft/GitHub-Copilot-for-Azure
Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.
Works with
Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization. Azure Kusto Irql Graph is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization.
Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql-graph -a claude-code`. Or copy the skill folder (plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/azure-kusto-irql-graph in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql-graph -a codex`. Or copy the skill folder (plugins/azure-kusto-graph-skills/skills/azure-kusto-irql-graph in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/azure-kusto-irql-graph in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql-graph -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-kusto-irql-graph, .gemini/skills/azure-kusto-irql-graph, .github/skills/azure-kusto-irql-graph and .opencode/skills/azure-kusto-irql-graph in your project.
SKILL.md names no scripts, command-line tools or credentials: Azure Kusto Irql Graph is instructions for the agent only.
SKILL.md names 2 domains. In commands or code: raw.githubusercontent.com and kc7001.eastus.kusto.windows.net; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azure Kusto Irql Graph is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Azure Kusto Irql Graph: Kql Validator (Azure/azqr, 795 stars), Kql (microsoft/fabric-rti-mcp, 131 stars), Apex Azure Diagnostics (jonathan-vella/apex, 217 stars) and Fleet Intelligence (microsoft/physical-ai-toolchain, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 9, 2026.
Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.