What problem does it solve?
It accelerates Azure security incident response by turning Defender alerts into a structured triage, investigation, containment, and escalation workflow with auditable documentation.
Core Features & Use Cases
- Triage severity and drive escalation: Classifies incidents into P0–P3 (with P0 forcing immediate CISO notification) based on impacted accounts/resources and alert context.
- Correlated investigation workflow: Pulls Defender alerts and relevant sign-in logs to build a timeline and determine likely initial access, lateral movement, persistence, and impact.
- Containment recommendations with approval gates: Recommends specific containment actions (e.g., revoke sessions, remove MFA methods, isolate devices) while explicitly requiring IT Manager approval for execution.
- Incident record creation and post-incident review guidance: Persists an incident record via MCP tools and outlines follow-up review timing for P0/P1.
Quick Start
Use incident-response with the alert ID or compromised user scope, for example: "Run incident-response for alert 12345 to triage, investigate, recommend containment, and create the incident record."