Agent Skills
› SCStelz/security-investigator
SCStelz/security-investigator
GitHub用于调查Azure Conditional Access策略变更与登录失败(如错误码53000/50074)的关联,通过时间线对比和KQL查询,分析并区分合法故障排查与安全控制绕过行为。
Install All Skills
npx skills add SCStelz/security-investigator --all -g -y
Skills in Collection (28)
用于调查Azure Conditional Access策略变更与登录失败(如错误码53000/50074)的关联,通过时间线对比和KQL查询,分析并区分合法故障排查与安全控制绕过行为。
用户询问Conditional Access或CA policy相关异常
检测到53000、50074等特定登录错误代码
怀疑存在策略绕过或权限滥用
npx skills add SCStelz/security-investigator --skill ca-policy-investigation -g -y
每周审查租户上下文记忆文件,比对最新安全扫描报告,生成仅建议的变更文档供人工审批。严格只读不修改,区分有效验证与回声数据,确保上下文准确性。
review my context file
review tenant context
propose context updates
what should I add to my context memory
npx skills add SCStelz/security-investigator --skill context-memory-review -g -y
通过 Microsoft Graph API 创建、部署和管理 Microsoft Defender XDR 自定义检测规则。涵盖 KQL 适配、单条及批量部署、生命周期管理及验证,解决权限与格式转换问题。
部署自定义检测规则
管理 Defender XDR 规则
KQL 转检测格式
批量导入检测规则
npx skills add SCStelz/security-investigator --skill detection-authoring -g -y
用于基于Microsoft Sentinel数据生成交互式世界地图可视化,展示攻击来源、地理位置分布及IP定位数据。
创建地理地图
可视化攻击来源
显示位置数据
IP地理定位分析
npx skills add SCStelz/security-investigator --skill geomap-visualization -g -y
基于Microsoft Sentinel数据生成交互式热力图,用于展示时间模式、活动网格及聚合矩阵数据,辅助识别异常与攻击行为。
创建热力图
可视化时间模式
显示活动网格
分析登录或攻击模式
npx skills add SCStelz/security-investigator --skill heatmap-visualization -g -y
用于分析蜜罐服务器安全,涵盖攻击模式、威胁情报关联、IP 丰富化及漏洞评估。通过并行查询和标准化报告生成,提供全面的安全分析与高管报告。
honeypot investigation
analyze honeypot
honeypot security
honeypot report
npx skills add SCStelz/security-investigator --skill honeypot-investigation -g -y
用于生成和验证Microsoft Sentinel及Defender XDR的KQL查询,通过MCP服务器进行模式校验、文档检索与性能优化。
编写或创建KQL查询
请求特定场景的数据分析查询
帮助处理KQL语法或逻辑
npx skills add SCStelz/security-investigator --skill kql-query-authoring -g -y
面向SOC日常操作的快速安全扫描技能,覆盖事件、身份、终端等7大领域。通过并行查询生成威胁仪表盘及下钻建议,适用于新手入门或日常巡检场景。
用户询问从哪里开始
用户询问系统能做什么
用户请求帮助调查
npx skills add SCStelz/security-investigator --skill threat-pulse -g -y
用于报告和分析 Microsoft AI Agent(如 Copilot Studio)的运行活动,包括用户、工具调用、渠道、Token 使用及安全拦截情况。
agent activity
AI agent usage
jailbreak activity
prompt injection activity
npx skills add SCStelz/security-investigator --skill ai-agent-activity -g -y
审计AI代理(Copilot等)的安全态势,涵盖库存、访问控制、工具权限、凭证暴露及数据外泄风险。通过查询AgentsInfo表生成全面评估报告。
AI agent posture
agent security audit
Copilot Studio agents
agent inventory
agent access
broadly accessible agents
agent tools
MCP tools on agents
agent knowledge sources
XPIA risk
agent sprawl
AI agent risk
agent governance
npx skills add SCStelz/security-investigator --skill ai-agent-posture -g -y
审计 Entra ID 应用注册和服务主体的安全态势,结合 Graph API 状态与 KQL 攻击链检测,评估权限、所有者风险、凭证卫生及横向移动。
app registration posture
service principal permissions
dangerous app permissions
app ownership
app credential abuse
npx skills add SCStelz/security-investigator --skill app-registration-posture -g -y
用于分析 Entra ID 认证流,通过 SessionId 和 IP 数据区分正常活动与令牌窃取,评估地理异常风险。
trace authentication
SessionId analysis
token reuse
geographic anomaly
impossible travel
npx skills add SCStelz/security-investigator --skill authentication-tracing -g -y
用于对Windows、macOS和Linux设备进行安全调查,分析Defender告警、登录模式、漏洞及合规性,适用于Entra ID注册设备的安全事件排查与风险评估。
investigate computer
investigate device
investigate endpoint
check machine
device security
endpoint investigation
npx skills add SCStelz/security-investigator --skill computer-investigation -g -y
分析Microsoft Purview和DLP数据安全事件,查询DataSecurityEvents表以审计敏感信息类型访问、标签变更及内部风险,支持大规模用户环境的钻取分析。
data security
sensitive information type
SIT access
DLP events
insider risk activity
Purview data security
sensitivity label
npx skills add SCStelz/security-investigator --skill data-security-analysis -g -y
基于Microsoft Defender for Office 365高级狩猎数据,生成邮件威胁防护报告。覆盖邮件流、威胁构成、钓鱼检测、认证有效性、ZAP修复及附件分析,评估组织邮件安全态势。
email threat report
email security posture
phishing report
MDO report
Defender for Office 365 report
ZAP effectiveness
Safe Links report
DMARC report
spam report
email volume report
npx skills add SCStelz/security-investigator --skill email-threat-posture -g -y
用于生成漏洞与暴露管理报告,评估组织或设备的安全态势。涵盖CVE、配置合规、终止支持软件、关键资产、攻击路径及证书状态等维度,支持全组织或单设备范围的分析与输出。
vulnerability report
exposure report
CVE assessment
security posture
vulnerability assessment
exposure management
patch status
end of support
security recommendations
attack paths
critical assets
configuration compliance
Defender device health
security score
TVM
threat and vulnerability management
npx skills add SCStelz/security-investigator --skill exposure-investigation -g -y
审计组织身份安全态势,涵盖账户清单、特权账号审查、闲置/删除账号清理、密码策略及多提供商身份关联分析。基于Microsoft Defender XDR高级查询数据,提供全面的安全评估报告。
identity posture
identity security report
account hygiene
stale accounts
privileged accounts
npx skills add SCStelz/security-investigator --skill identity-posture -g -y
用于调查 Microsoft Defender XDR 和 Sentinel 安全事件。通过检索元数据、警报及资产,引导用户选择实体(用户、设备、IoC)进行深度调查取证。
investigate incident
incident ID
incident investigation
analyze incident
triage incident
npx skills add SCStelz/security-investigator --skill incident-investigation -g -y
用于调查IP、域名、URL或文件哈希等入侵指标(IoC)的安全技能。通过关联Microsoft Defender威胁情报、CVE及资产暴露情况,提供全面的安全分析与取证支持。
investigate IP
check domain
IoC investigation
threat intel
is this malicious
suspicious URL
npx skills add SCStelz/security-investigator --skill ioc-investigation -g -y
用于监控和审计 Microsoft Sentinel 及 Defender XDR 环境中 MCP 服务器的使用情况,分析遥测数据、用户行为、API 调用模式及安全风险评估。
MCP usage
MCP server monitoring
MCP audit
tool usage monitoring
npx skills add SCStelz/security-investigator --skill mcp-usage-monitoring -g -y
生成MITRE ATT&CK检测覆盖率报告,通过自动化脚本收集分析规则、自定义检测及告警数据,映射至ATT&CK框架,识别覆盖缺口并提供优化建议。
需要评估安全检测策略对MITRE ATT&CK框架的覆盖情况
生成SOC检测能力审计报告
识别未标记或覆盖不足的检测规则
npx skills add SCStelz/security-investigator --skill mitre-coverage-report -g -y
用于检测终端设备进程执行行为的范围漂移,通过对比基线与近期活动计算加权漂移得分,识别渐进式异常扩展及潜在安全威胁。
设备漂移
端点行为偏差
进程基线检查
设备行为变化调查
npx skills add SCStelz/security-investigator --skill scope-drift-detection-device -g -y
用于检测 Entra ID 服务主体范围漂移的技能,通过构建90天行为基线并与近期活动对比,计算加权漂移得分,识别权限或行为的渐进式异常扩张。
scope drift
service principal drift
SPN behavioral change
automation account drift
baseline deviation
access expansion
npx skills add SCStelz/security-investigator --skill scope-drift-detection-spn -g -y
用于检测 Entra ID 用户账号的范围漂移,通过构建90天行为基线并与近期活动对比,计算加权漂移分数,识别权限、访问或行为的渐进式异常扩张。
user drift
user behavioral change
user scope drift
investigating user access expansion
npx skills add SCStelz/security-investigator --skill scope-drift-detection-user -g -y
基于YAML和PowerShell自动收集Azure Sentinel数据,通过LLM生成包含用量、异常、规则健康及优化建议的综合分析报告。
需要分析Azure Sentinel工作区的数据摄入量和成本
检测数据摄入异常或分析规则健康状况
评估Tier迁移候选项或许可证收益
npx skills add SCStelz/security-investigator --skill sentinel-ingestion-report -g -y
根据技能报告或调查数据生成SVG数据可视化仪表板,支持基于YAML清单的结构化模式和自由自适应模式。
generate SVG dashboard
create a visual dashboard
visualize this report
SVG from the report
visualize results
create SVG chart
SVG from this data
npx skills add SCStelz/security-investigator --skill svg-dashboard -g -y
将威胁情报文章转化为经过测试和调优的狩猎活动,解析RSS/Atom源,筛选相关文章,编写并验证KQL查询,输出标准化的活动文件及结构化管理数据。
threat intel campaign
ingest threat intelligence
TI feed
write hunts from this article
threat intelligence blog
build a hunting campaign
npx skills add SCStelz/security-investigator --skill threat-intel-campaign -g -y
用于调查Entra ID用户账户的安全问题、可疑活动或合规审查,分析登录异常、MFA状态及设备合规性。
investigate user
security investigation
user investigation
check user activity
analyze sign-ins
npx skills add SCStelz/security-investigator --skill user-investigation -g -y


