defensive-log-analysis

Reference KQL log tables and retention policies for Sentinel deployments.

1|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/riparino/Claude-Cyber --skill defensive-log-analysis
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: defensive-log-analysis
Source: https://github.com/riparino/Claude-Cyber/tree/main/Claude-Blue/Skills/defensive-log-analysis
Command: npx skills add https://github.com/riparino/Claude-Cyber --skill defensive-log-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill provides a centralized reference for log data sources, onboarding, normalization, and retention policies to help analysts configure and verify telemetry across environments.

Core Features & Use Cases

  • KQL table reference: fast lookups of the most common log tables (DeviceProcessEvents, SigninLogs, AzureDiagnostics, etc.) and how they map to investigations.
  • Onboarding & Retention guidance: step-by-step guidance for log source onboarding and retention policy mapping.
  • Operational reference for Sentinel deployments: quick validation of coverage and queries for regular reporting and incident response.

Quick Start

Query the KQL table reference to validate log coverage and retention for Sentinel deployments.

Frequently Asked Questions about defensive-log-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I configure log ingestion and retention policies for Sentinel deployments?

This skill provides KQL table references for common log tables like DeviceProcessEvents, SigninLogs, and AzureDiagnostics, mapping them directly to security investigations to help you validate log coverage and query data accurately.

What is the best way to onboard Entra ID monitoring logs into a SIEM?

You can validate Sentinel log coverage by querying the KQL table reference to check for common log tables like SigninLogs and AzureDiagnostics, ensuring proper log source onboarding and retention policy mapping for regular reporting and incident response.

Does this log analysis approach work with Microsoft Defender for Endpoint data?

You can validate Sentinel log coverage by querying the KQL table reference to check for common log tables like SigninLogs and AzureDiagnostics, ensuring proper log source onboarding and retention policy mapping for regular reporting and incident response.

How do I map KQL tables to specific security investigation scenarios?

You can validate Sentinel log coverage by querying the KQL table reference to check for common log tables like SigninLogs and AzureDiagnostics, ensuring proper log source onboarding and retention policy mapping for regular reporting and incident response.

When do I need to verify retention policies for Azure resource logs?

You can validate Sentinel log coverage by querying the KQL table reference to check for common log tables like SigninLogs and AzureDiagnostics, ensuring proper log source onboarding and retention policy mapping for regular reporting and incident response.