incident-investigation

Coordinate multi-phase security incident investigations across Microsoft Defender XDR and Sentinel.

2|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/msandbu/sentinelday --skill incident-investigation-msandbu
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: incident-investigation
Source: https://github.com/msandbu/sentinelday/tree/main/.github/skills/incident-investigation
Command: npx skills add https://github.com/msandbu/sentinelday --skill incident-investigation-msandbu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates the comprehensive investigation of security incidents within Microsoft Sentinel and Defender XDR, reducing manual triage time and improving incident response accuracy.

Core Features & Use Cases

  • Automated Data Collection: Gathers incident metadata, alerts, assets, and evidence from various sources.
  • Entity-Specific Investigation: Leverages specialized sub-skills (user-investigation, computer-investigation, ioc-investigation) for in-depth analysis of users, devices, and indicators of compromise.
  • Interactive Triage: Guides the analyst through a phased investigation, allowing them to select entities for deeper analysis.
  • Use Case: When a high-severity incident is reported, this Skill can automatically pull all related alerts, identify involved users and machines, and then allow the analyst to choose which specific user or device to investigate further, providing a structured and efficient workflow.

Quick Start

Use the incident-investigation skill to investigate incident ID '12345'.

Frequently Asked Questions about incident-investigation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security incident triage in Microsoft Defender XDR and Sentinel?

Security incident investigation automates comprehensive data collection of metadata, alerts, assets, and evidence from Microsoft Defender XDR and Sentinel, orchestrating sub-skills for in-depth analysis of users, devices, and indicators of compromise.

What is the process for deep diving into security incidents using Microsoft Sentinel?

Deep diving into security incidents involves pulling all related alerts, identifying involved entities, and guiding analysts through interactive phased triage to select specific users or devices for further investigation.

Can I investigate specific users and devices during an incident response with Defender XDR?

Yes, incident response with Defender XDR leverages specialized sub-skills for user-investigation, computer-investigation, and ioc-investigation to provide entity-specific analysis of users, devices, and indicators of compromise.

Does the incident investigation workflow require mandatory workspace selection for Microsoft Sentinel?

Yes, the incident investigation workflow requires mandatory workspace selection to properly query and retrieve incident metadata, alerts, assets, and evidence from Microsoft Sentinel.

How does interactive entity prioritization work during security incident forensics?

Interactive entity prioritization during security forensics allows analysts to manually select specific involved users or machines identified in the alert data for deeper, targeted analysis.

What is the best way to handle high-severity alerts and identify involved machines in Defender XDR?

The best way to handle high-severity alerts is to automatically pull all related alerts, identify involved users and machines, and allow analysts to choose which specific device to investigate further.