computer-investigation

Analyze Microsoft Defender and Entra ID data for device security investigations.

2|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/msandbu/sentinelday --skill computer-investigation-msandbu
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: computer-investigation
Source: https://github.com/msandbu/sentinelday/tree/main/.github/skills/computer-investigation
Command: npx skills add https://github.com/msandbu/sentinelday --skill computer-investigation-msandbu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill provides a comprehensive security investigation for any computer, device, or endpoint, identifying suspicious activity, malware, and compliance issues.

Core Features & Use Cases

  • Multi-faceted Analysis: Examines Defender alerts, sign-in patterns, logged-on users, software, vulnerabilities, and network activity.
  • Device Type Support: Works with Entra Joined, Hybrid Joined, and Entra Registered devices.
  • Use Case: When an alert indicates a potential compromise on a specific workstation, this Skill can be used to gather all relevant telemetry to confirm or deny the compromise and identify its scope.

Quick Start

Investigate the security status of the device named 'WORKSTATION-001' for the last 7 days.

Frequently Asked Questions about computer-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate a device security alert using Microsoft Defender for Endpoint telemetry?

To investigate a device security alert, this Skill analyzes Microsoft Defender for Endpoint telemetry to identify suspicious activity, malware, and compliance issues across Windows, macOS, and Linux devices. It examines alerts, sign-in patterns, and network activity to confirm potential compromises.

Does device investigation work with Entra Registered and Hybrid Joined devices?

Yes, device investigation works with Entra Joined, Hybrid Joined, and Entra Registered devices. It analyzes Microsoft Entra ID data alongside Defender alerts to identify security issues and suspicious activity across these various device join types.

What is the best way to check endpoint security and compliance status across multiple operating systems?

The best way to check endpoint security across operating systems is by analyzing Defender telemetry and Entra ID data. This Skill examines Windows, macOS, and Linux devices to identify malware, vulnerabilities, and compliance status in a single investigation.

Can I analyze Microsoft Entra ID sign-in patterns during a workstation compromise investigation?

Yes, you can analyze Microsoft Entra ID sign-in patterns during a workstation compromise investigation. The Skill examines sign-in data, logged-on users, and Defender alerts to identify suspicious activity and confirm the scope of potential security threats.

What data do I need to identify malware and vulnerabilities on a specific workstation?

To identify malware and vulnerabilities, you need the accurate device name and access to Microsoft Defender for Endpoint data. The Skill retrieves alerts, software inventories, and network activity to perform a comprehensive security investigation on the target workstation.