Agent Skills
› SCStelz/security-investigator
SCStelz/security-investigator
GitHub用于调查微软条件访问策略变更与登录失败关联的技能,检测合法排障、安全控制绕过及权限滥用。通过对比策略修改与错误日志时间线,分析53000等错误代码,识别未经授权的策略调整。
Install All Skills
npx skills add SCStelz/security-investigator --all -g -y
Skills in Collection (28)
用于调查微软条件访问策略变更与登录失败关联的技能,检测合法排障、安全控制绕过及权限滥用。通过对比策略修改与错误日志时间线,分析53000等错误代码,识别未经授权的策略调整。
Conditional Access policy changes
sign-in failures related to CA policies
suspected policy bypass/manipulation
investigate why a user was blocked then suddenly unblocked
npx skills add SCStelz/security-investigator --skill ca-policy-investigation -g -y
用于定期审查租户上下文记忆文件,对比最新扫描报告和调查日志,生成仅包含新增、修改或标记建议的评审文档供人工审批。严格禁止直接修改源文件或提交代码,确保变更安全可控。
review my context file
review tenant context
propose context updates
compact findings to memory
what should I add to my context memory
npx skills add SCStelz/security-investigator --skill context-memory-review -g -y
通过 Graph API 在 Microsoft Defender XDR 中创建、部署和管理自定义检测规则,涵盖 KQL 适配、批量部署及生命周期管理。
部署自定义检测规则
将 Sentinel KQL 转换为 Defender 格式
管理 Defender XDR 检测规则生命周期
npx skills add SCStelz/security-investigator --skill detection-authoring -g -y
用于基于Microsoft Sentinel数据生成交互式地理地图可视化,展示攻击来源、威胁分布及IP地理位置信息。
创建地理地图
可视化攻击来源
显示位置数据
IP地理定位分析
geomap
world map
geographic
npx skills add SCStelz/security-investigator --skill geomap-visualization -g -y
用于生成 Microsoft Sentinel 数据的热力图可视化,展示时间、实体或事件的聚合模式与异常。
创建热力图
可视化随时间变化的模式
显示活动网格
分析攻击或登录分布
npx skills add SCStelz/security-investigator --skill heatmap-visualization -g -y
用于分析蜜罐服务器安全事件的专业技能,涵盖攻击模式识别、威胁情报关联、IP丰富化及漏洞评估,并自动生成包含时间追踪的标准化执行报告。
honeypot investigation
analyze honeypot
honeypot security
honeypot report
npx skills add SCStelz/security-investigator --skill honeypot-investigation -g -y
用于生成和验证 Microsoft Sentinel、Defender XDR 及 Azure Data Explorer 的 KQL 查询。通过 MCP 服务器进行 Schema 校验、文档参考及社区示例匹配,确保生产级查询的性能与准确性。
编写 KQL 查询
创建 KQL 查询
KQL 查询辅助
查询特定数据表
特定场景的 KQL 需求
npx skills add SCStelz/security-investigator --skill kql-query-authoring -g -y
Threat Pulse 是面向安全运营中心(SOC)的快速扫描技能,通过并行执行12个查询覆盖7大安全领域,生成威胁仪表盘及下钻建议。适用于新用户入门、日常巡检或“仅15分钟”的紧急概览场景,提供从事件、身份到端点的全面风险视图。
用户询问如何开始使用或系统能做什么
请求帮助进行调查或获取安全态势概览
需要快速执行全领域安全扫描
npx skills add SCStelz/security-investigator --skill threat-pulse -g -y
分析AI代理运行时活动,涵盖使用量、工具调用及Prompt Shield安全 verdict。自动适配数据源,支持租户/代理/用户维度,用于行为监控与安全调查。
agent activity
AI agent usage
jailbreak activity
prompt injection activity
Agent 365 activity
npx skills add SCStelz/security-investigator --skill ai-agent-activity -g -y
审计AI代理(Copilot Studio、M365 Copilot等)的安全态势,通过Advanced Hunting查询AgentInfo表,评估代理库存、访问权限、工具暴露、凭据泄露及XPIA风险。
AI agent security audit
agent inventory
agent sprawl
agent governance
XPIA risk
credential exposure
npx skills add SCStelz/security-investigator --skill ai-agent-posture -g -y
审计Entra ID应用注册和服务主体的安全态势,结合Graph API权限盘点与KQL攻击链检测,评估权限集中、所有者风险、凭证卫生及活跃滥用信号。
app registration posture
service principal permissions
dangerous app permissions
app ownership
app credential abuse
SPN lateral movement
npx skills add SCStelz/security-investigator --skill app-registration-posture -g -y
用于追踪 Entra ID 认证流程,分析 SessionId 链、令牌复用及地理异常,区分合法活动与凭证窃取。
trace authentication
SessionId analysis
token reuse
geographic anomaly
npx skills add SCStelz/security-investigator --skill authentication-tracing -g -y
用于对Windows、macOS和Linux设备进行安全调查,分析Defender告警、登录模式、漏洞及合规性,适用于Entra ID管理设备的安全事件排查与审计。
investigate computer
investigate device
investigate endpoint
check machine
device security
endpoint investigation
npx skills add SCStelz/security-investigator --skill computer-investigation -g -y
分析Microsoft Purview数据安全事件,涵盖SIT访问、DLP匹配及敏感度标签审计。支持大规模环境下的用户下钻、文件清单生成及Copilot数据暴露风险排查,提供KQL查询与可视化报告。
data security
sensitive information type
SIT access
DLP events
insider risk activity
Purview data security
sensitivity label
label downgrade
Copilot label exposure
npx skills add SCStelz/security-investigator --skill data-security-analysis -g -y
基于Defender for Office 365遥测数据生成邮件威胁防护报告,评估安全态势。涵盖邮件流、威胁构成、钓鱼防护、认证及ZAP等,提供C级可见性。
email threat report
email security posture
phishing report
MDO report
Defender for Office 365 report
ZAP effectiveness
Safe Links report
DMARC report
spam report
email volume report
npx skills add SCStelz/security-investigator --skill email-threat-posture -g -y
生成漏洞与暴露管理报告,评估组织或设备的安全态势。涵盖CVE、配置合规、攻击路径及证书状态等,通过查询TVM相关表提供全面安全建议。
vulnerability report
security posture
CVE assessment
exposure management
attack paths
npx skills add SCStelz/security-investigator --skill exposure-investigation -g -y
审计组织身份安全态势,利用Defender XDR查询统一身份图谱。涵盖账号盘点、特权审计、闲置/删除账号清理、密码策略、风险分布及多提供商关联分析,提供全面的安全评估报告。
identity posture
identity security report
account hygiene
stale accounts
privileged accounts
password posture
identity providers
multi-provider identity
identity sprawl
service accounts
deleted accounts with roles
cross-IdP
honeytoken
sensitive accounts
npx skills add SCStelz/security-investigator --skill identity-posture -g -y
用于调查 Microsoft Defender XDR 和 Sentinel 安全事件的技能,支持按 ID 检索元数据、告警及资产证据,并引导用户对用户、设备或 IoC 进行深度分析。
investigate incident
incident ID
incident investigation
analyze incident
triage incident
npx skills add SCStelz/security-investigator --skill incident-investigation -g -y
用于调查恶意指标(IoC)如IP、域名、URL和文件哈希的安全技能。通过关联威胁情报、CVE漏洞及组织暴露面,评估安全风险并提供缓解建议。
investigate IP
check domain
IoC investigation
threat intel
is this malicious
suspicious URL
npx skills add SCStelz/security-investigator --skill ioc-investigation -g -y
监控审计 Microsoft Sentinel 及 Defender XDR 环境中 MCP 服务器使用情况,分析遥测数据、用户行为、API调用模式及安全风险。
MCP usage
MCP server monitoring
MCP audit
tool usage monitoring
npx skills add SCStelz/security-investigator --skill mcp-usage-monitoring -g -y
生成MITRE ATT&CK检测覆盖报告,自动收集分析规则、自定义检测及告警数据,映射至ATT&CK框架,识别覆盖缺口并提供优化建议。
需要评估安全检测对MITRE框架的覆盖率
查找未标记或覆盖不足的攻击技术
生成SOC优化与威胁场景对齐建议
npx skills add SCStelz/security-investigator --skill mitre-coverage-report -g -y
用于检测终端设备进程执行行为的渐进式范围漂移。通过构建基线并对比近期活动,计算多维度漂移得分,识别异常进程、账户及命令模式,支持单设备和全舰队模式分析。
device drift
endpoint behavioral change
process baseline deviation
npx skills add SCStelz/security-investigator --skill scope-drift-detection-device -g -y
用于检测 Entra ID 服务主体(SPN)的范围漂移、行为扩张或权限逐渐蠕变。通过构建90天基线并与7天近期活动对比,计算加权漂移分数,关联安全日志以发现缓慢演进的异常访问模式。
scope drift detection
service principal behavioral change
automation account drift
baseline deviation investigation
npx skills add SCStelz/security-investigator --skill scope-drift-detection-spn -g -y
用于检测 Entra ID 用户账号的范围漂移、行为扩展或权限渐进式滥用。通过建立90天基线并与近期活动对比,计算多维漂移得分,关联安全日志与审计记录,识别缓慢的异常访问模式。
用户范围漂移检测
用户行为变化分析
用户权限扩张调查
用户基线偏离评估
npx skills add SCStelz/security-investigator --skill scope-drift-detection-user -g -y
生成Azure Sentinel数据摄入分析报告,涵盖体积、异常检测、规则健康及成本优化建议。通过YAML驱动PowerShell采集数据,LLM渲染报告。
分析Sentinel工作区数据摄入情况
评估安全检测覆盖率和规则健康度
生成数据摄入成本与优化建议报告
npx skills add SCStelz/security-investigator --skill sentinel-ingestion-report -g -y
根据技能报告或调查数据生成SVG数据可视化仪表盘。支持基于YAML清单的结构化模式和自由形式的自适应可视化,提供多种图表组件。
generate SVG dashboard
create a visual dashboard
visualize this report
SVG from the report
visualize results
create SVG chart
SVG from this data
npx skills add SCStelz/security-investigator --skill svg-dashboard -g -y
将威胁情报文章转化为经过测试和优化的KQL狩猎活动。自动解析RSS/Atom源,评估相关性,生成并验证狩猎查询,输出标准化活动文件及结构化结果,不执行Git操作。
threat intel campaign
ingest threat intelligence
TI feed
write hunts from this article
threat intelligence blog
build a hunting campaign
npx skills add SCStelz/security-investigator --skill threat-intel-campaign -g -y
用于调查Entra ID用户账户的安全问题、可疑活动或合规审查。涵盖登录异常、MFA状态、设备合规性及审计日志分析,支持生成HTML/Markdown报告及SVG仪表盘,提供快捷排查路径。
investigate user
security investigation
user investigation
check user activity
analyze sign-ins
npx skills add SCStelz/security-investigator --skill user-investigation -g -y


