Agent Skills by Marius Sandbu
Showing 17 vetted skills indexed across 1 GitHub repositories.
detection-authoring
Deploy and manage Microsoft Defender XDR detection rules via Graph API.
user-investigation
Analyzes Microsoft Entra ID user accounts for security risks and anomalies.
kql-query-authoring
Generate validated KQL queries for Microsoft Sentinel and Defender XDR.
exposure-investigation
Query DeviceTvm* and ExposureGraph* tables to generate vulnerability and exposure management reports.
mcp-usage-monitoring
Monitor MCP server usage across Microsoft Sentinel and Defender XDR environments.
heatmap-visualization
Generate interactive heatmaps from Microsoft Sentinel data using KQL-aggregated inputs.
sentinel-ingestion-report
Analyze Microsoft Sentinel ingestion patterns, table volumes, and anomalies via PowerShell.
authentication-tracing
Analyze Microsoft Entra ID authentication flows to detect token theft.
ca-policy-investigation
Correlate Conditional Access policy changes with sign-in failure error codes.
honeypot-investigation
Automates security analysis of honeypot servers by querying failed connections and enriching IPs with threat intelligence.
incident-investigation
Coordinate multi-phase security incident investigations across Microsoft Defender XDR and Sentinel.
computer-investigation
Analyze Microsoft Defender and Entra ID data for device security investigations.
ioc-investigation
Investigate IP addresses, domains, URLs, and file hashes with threat intelligence correlation.
geomap-visualization
Generates interactive geographic maps of IP addresses to visualize attack origins and security events.
scope-drift-detection-user
Detect scope drift in Entra ID user accounts using 90-day behavioral baselines.
scope-drift-detection-spn
Detect scope drift in Entra ID service principals using 90-day behavioral baselines.
scope-drift-detection-device
Detect scope drift and behavioral baseline deviation in DeviceProcessEvents.