Agent Skills › SCStelz/security-investigator

SCStelz/security-investigator

GitHub

用于调查微软 Conditional Access (CA) 策略变更与登录失败(如错误码53000)的关联,通过时间线对比分析,区分合法故障排除与安全控制绕过或权限滥用行为。

28 skills 239

Install All Skills

npx skills add SCStelz/security-investigator --all -g -y
More Options

List skills in collection

npx skills add SCStelz/security-investigator --list

Skills in Collection (28)

用于调查微软 Conditional Access (CA) 策略变更与登录失败(如错误码53000)的关联,通过时间线对比分析,区分合法故障排除与安全控制绕过或权限滥用行为。
Conditional Access policy changes investigation Sign-in failures related to CA policies Suspected policy bypass or manipulation Investigating why a user was blocked then suddenly unblocked
.github/skills/ca-policy-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill ca-policy-investigation -g -y
用于定期审查租户上下文记忆文件,对比最新安全扫描报告,生成包含新增、修改或标记建议的提案文档。该技能仅只读分析并输出审查结果,严禁直接修改文件或提交代码,需人工确认后再应用变更。
review my context file review tenant context propose context updates what should I add to my context memory
.github/skills/context-memory-review/SKILL.md
npx skills add SCStelz/security-investigator --skill context-memory-review -g -y
通过Microsoft Graph API在Defender XDR中创建、部署和管理自定义检测规则。支持KQL查询适配、单条或批量部署、生命周期管理及验证,解决API权限与格式转换问题。
需要部署自定义检测规则到Defender XDR 将Sentinel KQL查询转换为Defender格式并应用 批量管理安全检测规则的启用、禁用或删除
.github/skills/detection-authoring/SKILL.md
npx skills add SCStelz/security-investigator --skill detection-authoring -g -y
基于Microsoft Sentinel数据生成交互式世界地图可视化,展示攻击来源、地理威胁分布及IP定位数据。支持通过MCP工具查询坐标并渲染带丰富情报的标记点。
创建地理地图 可视化攻击来源 显示位置数据 IP地理定位 geomap world map geographic attack map show on map visualize locations attack origins
.github/skills/geomap-visualization/SKILL.md
npx skills add SCStelz/security-investigator --skill geomap-visualization -g -y
基于Microsoft Sentinel数据生成交互式热力图,用于识别时间或实体模式。通过MCP工具展示聚合数据,支持KQL查询及威胁情报 enrichment,辅助安全分析。
创建热力图 可视化时间模式 显示活动网格 分析攻击模式
.github/skills/heatmap-visualization/SKILL.md
npx skills add SCStelz/security-investigator --skill heatmap-visualization -g -y
用于分析蜜罐服务器安全性的智能体,涵盖攻击模式识别、威胁情报关联、IP 丰富化及漏洞评估,并生成包含时间追踪的合规执行报告。
honeypot investigation analyze honeypot honeypot security honeypot report
.github/skills/honeypot-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill honeypot-investigation -g -y
用于生成经过验证的、生产就绪的KQL查询。结合模式验证、官方文档和社区示例,针对Microsoft Sentinel和Defender XDR等场景编写高质量查询。
write KQL create KQL query help with KQL query [table] KQL for [scenario]
.github/skills/kql-query-authoring/SKILL.md
npx skills add SCStelz/security-investigator --skill kql-query-authoring -g -y
Threat Pulse 是面向 SOC 日常运营的快速安全扫描技能,覆盖事件、身份、终端等7大领域,并行执行12项查询生成威胁仪表盘及钻取建议,适用于新手入门或每日例行安全检查。
where do I start what can you do help me investigate
.github/skills/threat-pulse/SKILL.md
npx skills add SCStelz/security-investigator --skill threat-pulse -g -y
用于报告和分析AI代理(如Copilot、Agent 365)的运行时活动,包括用户行为、工具调用、令牌使用及安全事件。自动检测数据平面,支持租户级或单用户/代理范围的活动监控与调查。
agent activity AI agent usage who is using agents jailbreak activity prompt injection activity
.github/skills/ai-agent-activity/SKILL.md
npx skills add SCStelz/security-investigator --skill ai-agent-activity -g -y
审计AI代理安全态势,涵盖库存、访问控制、工具权限及凭证暴露等风险。利用Defender XDR查询数据,评估Copilot Studio等多平台代理配置与治理状态。
AI agent posture agent security audit Copilot Studio agents XPIA risk agent sprawl
.github/skills/ai-agent-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill ai-agent-posture -g -y
审计 Entra ID 应用注册和服务主体的安全态势,结合 Graph API 状态清单与 KQL 攻击链检测,评估权限、所有者风险、凭证卫生及活跃滥用信号。
app registration posture service principal permissions dangerous app permissions app ownership app credential abuse SPN lateral movement app consent grant overprivileged apps cross-tenant SPN app registration kill chain app persistence credential add chain Graph API permissions audit
.github/skills/app-registration-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill app-registration-posture -g -y
用于追踪 Entra ID 认证流程,分析 SessionId 链、令牌复用及地理异常。通过区分主动 MFA 与刷新令牌,进行取证分析以识别凭证窃取或合法活动。
trace authentication SessionId analysis token reuse geographic anomaly impossible travel
.github/skills/authentication-tracing/SKILL.md
npx skills add SCStelz/security-investigator --skill authentication-tracing -g -y
用于对受管计算机、设备或端点进行安全调查,分析恶意软件、可疑活动及合规性。支持多种调查类型和快捷路径,提供详细报告。
investigate computer check machine security endpoint investigation
.github/skills/computer-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill computer-investigation -g -y
分析Microsoft Purview和Defender XDR中的数据安全事件,查询DataSecurityEvents表以审计敏感信息类型(SIT)访问、DLP匹配、敏感度标签变更及Copilot数据暴露风险。
data security sensitive information type SIT access DLP events insider risk activity Purview data security sensitivity label label downgrade Copilot label exposure
.github/skills/data-security-analysis/SKILL.md
npx skills add SCStelz/security-investigator --skill data-security-analysis -g -y
基于Microsoft Defender for Office 365遥测数据,生成邮件威胁保护态势报告。涵盖邮件流、威胁组成、反钓鱼、认证、ZAP补救及安全事件分析,提供C级安全可见性。
email threat report email security posture phishing report MDO report Defender for Office 365 report ZAP effectiveness Safe Links report DMARC report spam report email volume report
.github/skills/email-threat-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill email-threat-posture -g -y
用于生成漏洞与暴露管理报告,评估组织或设备的安全态势。涵盖CVE、配置合规、终止支持软件、关键资产、攻击路径及证书状态等,通过查询特定数据表提供全面的安全建议。
vulnerability report exposure report CVE assessment security posture attack paths
.github/skills/exposure-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill exposure-investigation -g -y
审计组织身份安全态势,利用 Defender XDR 高级狩猎功能评估账户清单、特权账号、闲置/已删除账号卫生、密码策略、风险分布及多提供商身份关联。
identity posture identity security report account hygiene stale accounts privileged accounts
.github/skills/identity-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill identity-posture -g -y
用于调查 Microsoft Defender XDR 和 Sentinel 中的安全事件。通过检索元数据、告警和资产,引导用户选择实体进行深度调查(用户、设备或 IoC),支持迭代式取证分析。
investigate incident incident ID incident investigation analyze incident triage incident
.github/skills/incident-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill incident-investigation -g -y
用于调查IP、域名、URL及文件哈希等入侵指标(IoC)的安全分析技能。结合Microsoft Defender威胁情报,执行关联分析、CVE匹配及设备暴露评估,提供自动化取证与风险报告。
investigate IP check domain IoC investigation threat intel is this malicious suspicious URL
.github/skills/ioc-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill ioc-investigation -g -y
监控和分析Microsoft Sentinel及Defender XDR环境中MCP服务器的使用情况,涵盖遥测分析、用户归属、敏感API检测及安全风险评估。
MCP usage MCP server monitoring MCP audit tool usage monitoring
.github/skills/mcp-usage-monitoring/SKILL.md
npx skills add SCStelz/security-investigator --skill mcp-usage-monitoring -g -y
生成MITRE ATT&CK覆盖报告,通过YAML驱动PowerShell管道收集检测规则、自定义检测及运营数据,映射战术与技术,识别覆盖缺口并提供SOC优化建议。
需要评估安全检测规则对MITRE框架的覆盖率时 分析检测规则与告警/事件的关联以识别覆盖盲区时
.github/skills/mitre-coverage-report/SKILL.md
npx skills add SCStelz/security-investigator --skill mitre-coverage-report -g -y
用于检测终端设备进程执行行为的范围漂移,通过建立基线对比近期活动,计算多维度漂移评分,识别渐进式异常行为。
device drift endpoint drift process baseline device behavioral change
.github/skills/scope-drift-detection/device/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-device -g -y
检测服务主体范围漂移,通过构建90天行为基线并与近期活动对比,计算加权漂移得分。适用于识别权限、访问或行为的渐进式异常扩展,结合安全日志进行关联分析。
scope drift service principal drift SPN behavioral change automation account drift baseline deviation access expansion
.github/skills/scope-drift-detection/spn/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-spn -g -y
用于检测 Entra ID 用户账号的范围漂移,通过构建90天行为基线与近期活动对比,计算加权漂移得分,结合安全告警、审计日志及云应用/邮件事件数据,识别权限或行为的渐进式异常扩张。
用户范围漂移检测 用户行为变化分析 用户基线偏离调查 访问权限逐渐扩大排查
.github/skills/scope-drift-detection/user/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-user -g -y
生成Azure Sentinel数据摄入分析报告,涵盖容量、层级分类、异常检测、规则健康及优化建议。通过YAML驱动PowerShell采集数据,LLM渲染最终报告。
需要分析Sentinel工作区的数据摄入量和成本结构 检测数据摄入异常或评估检测覆盖度 评估Tier迁移候选项或许可证收益
.github/skills/sentinel-ingestion-report/SKILL.md
npx skills add SCStelz/security-investigator --skill sentinel-ingestion-report -g -y
根据技能报告或调查数据生成SVG可视化仪表板。支持基于YAML清单的结构化模式和基于上下文的自由形式模式,涵盖多种图表组件。
generate SVG dashboard create a visual dashboard visualize this report SVG from the report visualize results create SVG chart SVG from this data
.github/skills/svg-dashboard/SKILL.md
npx skills add SCStelz/security-investigator --skill svg-dashboard -g -y
将威胁情报文章转化为经过测试和调优的狩猎活动。通过RSS/Atom订阅源或单篇文章URL,执行相关性筛选、KQL查询编写与测试,最终生成标准化的狩猎活动文件及结构化结果,不执行Git操作。
threat intel campaign ingest threat intelligence TI feed write hunts from this article threat intelligence blog build a hunting campaign
.github/skills/threat-intel-campaign/SKILL.md
npx skills add SCStelz/security-investigator --skill threat-intel-campaign -g -y
用于调查Entra ID用户账户的安全问题、可疑活动或合规审查。涵盖登录异常、MFA状态、设备合规性、审计日志及身份保护风险,支持生成HTML、Markdown或内联报告。
investigate user security investigation user investigation check user activity analyze sign-ins
.github/skills/user-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill user-investigation -g -y

Accueil - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-29 15:29
浙ICP备14020137号-1 $Carte des visiteurs$