Marius Sandbu avatar

Marius Sandbu

Community

@msandbu

69Followers
|
51Public Repos
|
17Published Skills

Agent Skills by Marius Sandbu

Showing 17 vetted skills indexed across 1 GitHub repositories.

msandbumsandbu
2

detection-authoring

Deploy and manage Microsoft Defender XDR detection rules via Graph API.

Community
Advanced
msandbumsandbu
2

user-investigation

Analyzes Microsoft Entra ID user accounts for security risks and anomalies.

Community
Advanced
msandbumsandbu
2

kql-query-authoring

Generate validated KQL queries for Microsoft Sentinel and Defender XDR.

Community
Advanced
msandbumsandbu
2

exposure-investigation

Query DeviceTvm* and ExposureGraph* tables to generate vulnerability and exposure management reports.

Community
Advanced
msandbumsandbu
2

mcp-usage-monitoring

Monitor MCP server usage across Microsoft Sentinel and Defender XDR environments.

Community
Advanced
msandbumsandbu
2

heatmap-visualization

Generate interactive heatmaps from Microsoft Sentinel data using KQL-aggregated inputs.

Community
Intermediate
msandbumsandbu
2

sentinel-ingestion-report

Analyze Microsoft Sentinel ingestion patterns, table volumes, and anomalies via PowerShell.

Community
Advanced
msandbumsandbu
2

authentication-tracing

Analyze Microsoft Entra ID authentication flows to detect token theft.

Community
Advanced
msandbumsandbu
2

ca-policy-investigation

Correlate Conditional Access policy changes with sign-in failure error codes.

Community
Advanced
msandbumsandbu
2

honeypot-investigation

Automates security analysis of honeypot servers by querying failed connections and enriching IPs with threat intelligence.

Community
Advanced
msandbumsandbu
2

incident-investigation

Coordinate multi-phase security incident investigations across Microsoft Defender XDR and Sentinel.

Community
Advanced
msandbumsandbu
2

computer-investigation

Analyze Microsoft Defender and Entra ID data for device security investigations.

Community
Advanced
msandbumsandbu
2

ioc-investigation

Investigate IP addresses, domains, URLs, and file hashes with threat intelligence correlation.

Community
Advanced
msandbumsandbu
2

geomap-visualization

Generates interactive geographic maps of IP addresses to visualize attack origins and security events.

Community
Advanced
msandbumsandbu
2

scope-drift-detection-user

Detect scope drift in Entra ID user accounts using 90-day behavioral baselines.

Community
Advanced
msandbumsandbu
2

scope-drift-detection-spn

Detect scope drift in Entra ID service principals using 90-day behavioral baselines.

Community
Advanced
msandbumsandbu
2

scope-drift-detection-device

Detect scope drift and behavioral baseline deviation in DeviceProcessEvents.

Community
Advanced