SCStelzSCStelzCommunityยท11 Agent Skills Included

security-investigator

Automated security investigations across Sentinel, Defender, and Entra ID

Runs natural-language security investigations across Microsoft Sentinel, Defender XDR, and Entra ID using 25 specialized workflows. Covers incident triage, user and device forensics, IoC enrichment, threat hunting, vulnerability posture, and MITRE ATT&CK coverage reporting. Eliminates manual KQL writing and portal clicking by executing validated queries and generating prioritized findings with reports and dashboards.
npx skills add SCStelz/security-investigator --all -g -y

All Skills in This Repository (11)

Pure Emerald Level Indicators
๐Ÿ“ฆ In Repo
SCStelzSCStelz

user-investigation

Analyze Entra ID user accounts for security issues and generate HTML reports.

Community
Advanced
๐Ÿ“ฆ In Repo
SCStelzSCStelz

kql-query-authoring

Generate validated KQL queries for Microsoft Sentinel, Defender XDR, and Azure Data Explorer.

Community
Advanced
๐Ÿ“ฆ In Repo
SCStelzSCStelz

scope-drift-detection

Detect and quantify scope drift across Entra ID service principals and user accounts.

Community
Advanced
๐Ÿ“ฆ In Repo
SCStelzSCStelz

heatmap-visualization

Generate interactive time-based heatmaps from MCP-enabled Sentinel data.

Community
Advanced
๐Ÿ“ฆ In Repo
SCStelzSCStelz

authentication-tracing

Trace Entra ID authentication flows to distinguish fresh MFA from token reuse.

Community
Advanced
๐Ÿ“ฆ In Repo
SCStelzSCStelz

ca-policy-investigation

Correlate Conditional Access policy changes with sign-in failures in Azure AD logs.

Community
Advanced
๐Ÿ“ฆ In Repo
SCStelzSCStelz

honeypot-investigation

Analyze honeypot servers to identify attack patterns and generate executive security reports.

Community
Advanced
๐Ÿ“ฆ In Repo
SCStelzSCStelz

incident-investigation

Orchestrate security incident investigations with Defender XDR and Sentinel MCP tools.

Community
Advanced
๐Ÿ“ฆ In Repo
SCStelzSCStelz

computer-investigation

Automate security investigations for Entra ID and Defender for Endpoint devices.

Community
Advanced
๐Ÿ“ฆ In Repo
SCStelzSCStelz

ioc-investigation

Investigate IoCs across Defender and Sentinel sources and export JSON reports.

Community
Advanced
๐Ÿ“ฆ In Repo
SCStelzSCStelz

geomap-visualization

Render interactive world maps of attack origins from Sentinel coordinate data.

Community
Advanced

Frequently Asked Questions

FAQPage Schema
How to install security-investigator?โ–ผ

Run `npx skills add SCStelz/security-investigator --all -g -y` in your terminal to install all 25 investigation skills globally.

What does security-investigator do?โ–ผ

It lets you ask plain-English questions like 'Investigate this user for the last 7 days' or 'Is this IP malicious?' and runs validated KQL queries against Microsoft Sentinel and Defender XDR, returning prioritized findings with reports.

How do I run a quick security scan?โ–ผ

Start with the Threat Pulse skill by asking 'Run a threat pulse scan'. It checks 7 security domains in about 15 minutes and gives color-coded verdicts with drill-down recommendations.

What prerequisites does security-investigator need?โ–ผ

You need a Microsoft Sentinel workspace, Defender XDR access, and API tokens for IP enrichment services (ipinfo, AbuseIPDB, Shodan) configured in config.json and .env files.

Can it generate reports and dashboards?โ–ผ

Yes. Every investigation can produce inline chat summaries, markdown reports, HTML reports, and SVG dashboards with risk scores, charts, and executive summaries.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’