Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.

MITAuto-check passedSecurity

Install Sentinel

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill sentinel -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills sentinel --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sentinel .claude/skills/sentinel && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sentinel
GitHub stars
175
Token cost
~2.2k tokens
SKILL.md length
966 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.

  • Works in 8 steps: Estimate volume and pick commitment tier… → Workspace design — Default to a single,… → Connect data sources in priority order —… → …
  • The goal is correlating Microsoft 365 XDR alerts into incidents (use defender-xdr)
  • SKILL.md covers When to use, Route the log source to the…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Sentinel is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal. Covers workspace design, data connectors, ingestion tiers (Analytics/Basic/Auxiliary/ADX), analytics rules, hunting, watchlists, automation playbooks, and cost/commitment-tier optimisation. WHEN: deploy Microsoft Sentinel, design SIEM, onboard data connectors, write analytics rule, KQL detection, Sentinel playbook, SOAR automation, Sentinel cost optimization, log ingestion tiers…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security operations, Cloud office suites and Incident response. It works with Microsoft Sentinel, Microsoft 365, Microsoft Defender and Microsoft Azure. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • The goal is correlating Microsoft 365 XDR alerts into incidents (use defender-xdr)
  • Onboarding Sentinel into the unified Defender portal (use unified-secops-platform)

Example prompts

  • “/sentinel”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Estimate volume and pick commitment tier — Run the Sentinel pricing calculator with a
  2. Workspace design — Default to a single, central Log Analytics workspace per tenant.
  3. Connect data sources in priority order — Top 5 connectors that cover ~80% of M365
  4. Enable solutions, not raw rules — Install from Content Hub (Entra solution, MDE
  5. Analytics rules - start broad, tune fast — Enable all built-in templates for installed
  6. Hunting and UEBA — Enable UEBA on Entra + on-prem AD data (IdentityInfo, BehaviorAnalytics
  7. Automation — Use automation rules for triage (assign, tag, close noisy true-positives)
  8. Cost review monthly — Check Usage table for top tables by volume; move low-value tables

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sentinel loads about 2.2k tokens when it runs. Until then it costs about 249 tokens; SKILL.md has 966 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~249
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 966 words, ~2,172 tokens.

Download SKILL.mdSave it as .claude/skills/sentinel/SKILL.md (or your agent's skills folder).
name
sentinel
description
Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal. Covers workspace design, data connectors, ingestion tiers (Analytics/Basic/Auxiliary/ADX), analytics rules, hunting, watchlists, automation playbooks, and cost/commitment-tier optimisation. WHEN: deploy Microsoft Sentinel, design SIEM, onboard data connectors, write analytics rule, KQL detection, Sentinel playbook, SOAR automation, Sentinel cost optimization, log ingestion tiers, commitment tier, Sentinel workspace design, how do I set up a SIEM, collect logs from third-party tools, ingest firewall or Linux syslog into Azure, write a detection rule, automate incident response, how much does Sentinel cost, Auxiliary logs, Basic logs, ADX archive, codeless connector. DO NOT USE when the goal is correlating Microsoft 365 XDR alerts into incidents (use defender-xdr) or onboarding Sentinel into the unified Defender portal (use unified-secops-platform).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Sentinel

Microsoft Sentinel is a cloud-native SIEM + SOAR built on a Log Analytics workspace and delivered through the Microsoft Defender portal as part of the unified SecOps platform. It ingests logs from Microsoft and third-party sources, runs scheduled and near-real-time detections in KQL, correlates alerts into incidents, and orchestrates response via Logic Apps playbooks.

When to use

Centralising security logs from Microsoft and third-party sources, building detections, hunting across data, and automating response. Use Sentinel when you need a single SIEM across clouds, on-prem, and SaaS - not only Microsoft 365.

Do not use this skill when the goal is only correlating M365 alerts (use defender-xdr) or onboarding the existing Sentinel workspace into the unified Defender portal (use unified-secops-platform).

Route the log source to the right ingestion tier

Pick the tier first, then the connector. Tier choice drives cost more than anything else.

If the log is...Send toRetention defaultCost shape
High-fidelity security log used in detections (sign-ins, audit, EDR)Analytics90 days free, then paidPay per GB (commitment tier)
Verbose but query-occasionally (CDN, custom app, firewall info)Basic logs30 days, no analytics rules~1/5th of Analytics
High-volume, low-fidelity, search-only (NetFlow, DNS, proxy)Auxiliary logs30 days hot + 12 mo long-term~1/8th of Analytics
Long-term archive for compliance / rare investigationAzure Data Explorer (ADX)YearsADX cluster cost
Microsoft 365 / Defender XDR alerts onlyFree via M365 Defender connectorN/AFree

Rule of thumb (2026 pricing): if a table averages > 50 GB/day and analytics rules don't query it, it does not belong in the Analytics tier. Moving DNS or proxy logs to Auxiliary typically cuts Sentinel bills by 30-50%.

Approach

  1. Estimate volume and pick commitment tier — Run the Sentinel pricing calculator with a 30-day sample (use Usage | summarize sum(Quantity) by bin(TimeGenerated, 1d), DataType). Commitment tiers start at 100 GB/day and drop the per-GB rate ~50% vs Pay-As-You-Go. Verify: daily ingestion stable within ±20% of estimate before committing.

  2. Workspace design — Default to a single, central Log Analytics workspace per tenant. Use Azure RBAC + table-level RBAC for scoping instead of splitting workspaces. Co-locate the workspace in the region where most data is generated to reduce egress and latency. Verify: cross-workspace queries are not needed for primary detections - if they are, you over-sharded.

  3. Connect data sources in priority order — Top 5 connectors that cover ~80% of M365 tenants: Entra ID (sign-in + audit), Office 365 (Exchange + SharePoint), Defender XDR (alerts + raw advanced hunting), Azure Activity, Microsoft Threat Intelligence. For third-party: Codeless Connector Platform > AMA/syslog/CEF > Logstash. Verify: union withsource=Tbl * | summarize count() by Tbl, bin(TimeGenerated, 1h) shows continuous ingestion - no flat-lines.

  4. Enable solutions, not raw rules — Install from Content Hub (Entra solution, MDE solution, etc.). You get the connector, parser, workbook, hunting queries, and analytics rules in one install. Tune the templates; don't write from scratch.

  5. Analytics rules - start broad, tune fast — Enable all built-in templates for installed solutions in near-real-time or scheduled mode. Expect 10-20 false-positive rules in the first week; tune entity mappings and thresholds rather than disabling. Group related alerts into incidents via incident-grouping settings.

  6. Hunting and UEBA — Enable UEBA on Entra + on-prem AD data (IdentityInfo, BehaviorAnalytics tables). Use built-in hunting queries weekly; promote useful hunts to scheduled rules.

  7. Automation — Use automation rules for triage (assign, tag, close noisy true-positives) and Logic Apps playbooks for response (notify Teams, enrich with TI, isolate device, disable user). Map every rule to MITRE ATT&CK for coverage reporting.

  8. Cost review monthly — Check Usage table for top tables by volume; move low-value tables to Basic/Auxiliary; set table-level retention deliberately. Watch for connector misconfig (debug logging left on).

Show full SKILL.md (365 more words)Show less

Guardrails

  • Estimate before committing. Commitment tiers are billed minimum daily; over-committing by 30% is more expensive than PAYG. Start PAYG for 30 days, then commit.
  • Avoid duplicate ingestion. Don't ingest Defender XDR raw events and advanced hunting unless a specific detection needs both - you pay twice.
  • Use table-level RBAC, not multiple workspaces. Workspace splits double connector cost, break cross-source detections, and complicate incident response.
  • Set retention per table. Default 90 days applies to all Analytics tables; rare-use tables (e.g. AzureActivity) can drop to 30 days, hot tables (SigninLogs) extend to 1 year.
  • Don't disable a noisy rule - tune it. Disabling removes the detection. Adjust entity mappings, threshold, or scope first.
  • Auxiliary logs cannot drive scheduled analytics rules. Don't move a table to Auxiliary if detections depend on it.

Common anti-patterns

  • "One workspace per business unit for isolation" - Doubles cost, breaks correlation. Use resource-context RBAC instead.
  • "We commit to 500 GB/day on day one" - Tier locks you in for 31 days. Always run PAYG baseline first.
  • "Ingest everything in case we need it" - Sentinel bills grow linearly with GB. Tier decision per table is the single biggest cost lever.
  • "We disabled the noisy detection rules" - Removed coverage instead of tuning. Use per-entity exclusions or threshold adjustment.
  • "All analytics rules at 5-minute schedule" - Burns query units and creates duplicate alerts. Match schedule to detection window (auth attacks 5 min, lateral movement 1 hour).
  • "Playbook on every rule" - Most rules need triage automation, not response. Reserve response playbooks for high-confidence detections.

Example prompts

  • Estimate Sentinel monthly cost for 200 GB/day across Entra ID, Defender XDR, and Azure firewall.
  • Should I split my Sentinel workspace by business unit or use table-level RBAC?
  • Move DNS and proxy logs from Analytics to Auxiliary - what breaks?
  • Which connectors should I enable first for a new M365 tenant?
  • Write a near-real-time analytics rule for impossible travel sign-ins.
  • Build a playbook that isolates a device and notifies Teams when MDE flags ransomware behaviour.
  • Audit my workspace - top 10 tables by ingestion and which can drop tier or retention.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sentinel of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Sentinel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sentinel compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sentinel this skillvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Azure Kusto Irqlmicrosoft/GitHub-Copilot-for-Azure255—~2.6kAutomated safety check: PassMIT
Forensics OsqueryAgentSecOps/SecOpsAgentKit2201 repos~4.9kAutomated safety check: NotesCustom licence
Detecting Spearphishing With Email Gatewaymukul975/Anthropic-Cybersecurity-Skills34k—~1.4kAutomated safety check: PassApache-2.0
Conducting Cloud Incident Responsemukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Detecting Azure Service Principal Abusemukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0

Similar skills

  • Azure Kusto Irql

    microsoft/GitHub-Copilot-for-Azure

    Official

    Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations.

    255 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    220 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Detecting Spearphishing With Email Gateway

    mukul975/Anthropic-Cybersecurity-Skills

    Detect and block spearphishing emails that use personalized, researched content to evade generic spam filters, by configuring email security gateway (SEG) impersonation protection, URL rewriting…

    34k GitHub stars~1.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Conducting Cloud Incident Response

    mukul975/Anthropic-Cybersecurity-Skills

    Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Detecting Azure Service Principal Abuse

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Privilege Escalation Attempts

    mukul975/Anthropic-Cybersecurity-Skills

    Detect privilege escalation attempts across Windows and Linux, including access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse.

    34k GitHub stars~922 tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Sentinel

What does Sentinel do?

Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal. Sentinel is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.

When should I use Sentinel?

Sentinel fits situations like: the goal is correlating Microsoft 365 XDR alerts into incidents (use defender-xdr); onboarding Sentinel into the unified Defender portal (use unified-secops-platform).

How do I install Sentinel in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill sentinel -a claude-code`. Or copy the skill folder (skills/sentinel in vinayaklatthe/microsoft-security-skills) into .claude/skills/sentinel in your project. Claude Code loads it when a task matches its description.

How do I install Sentinel in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill sentinel -a codex`. Or copy the skill folder (skills/sentinel in vinayaklatthe/microsoft-security-skills) into .agents/skills/sentinel in your project. Codex loads it when a task matches its description.

Can I use Sentinel in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill sentinel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sentinel, .gemini/skills/sentinel, .github/skills/sentinel and .opencode/skills/sentinel in your project.

What does Sentinel need to run?

SKILL.md names no scripts, command-line tools or credentials: Sentinel is instructions for the agent only.

Does Sentinel access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Sentinel safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sentinel use?

Sentinel is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sentinel use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sentinel?

Skills that share tags, products or a category with Sentinel: Azure Kusto Irql (microsoft/GitHub-Copilot-for-Azure, 255 stars), Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars), Detecting Spearphishing With Email Gateway (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Conducting Cloud Incident Response (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sentinel?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.