Agent Skills › SCStelz/security-investigator

SCStelz/security-investigator

GitHub

用于调查条件访问策略变更与登录失败(如53000、50074)的关联,区分合法故障排除与安全控制绕过。通过强制步骤分析策略状态转换和时间线,识别特权滥用或未经授权的修改。

27 个 Skill 231

安装全部 Skills

npx skills add SCStelz/security-investigator --all -g -y
更多选项

预览集合内 Skills

npx skills add SCStelz/security-investigator --list

集合内 Skills (27)

用于调查条件访问策略变更与登录失败(如53000、50074)的关联,区分合法故障排除与安全控制绕过。通过强制步骤分析策略状态转换和时间线,识别特权滥用或未经授权的修改。
Conditional Access CA policy device compliance policy bypass 53000 50074 用户被阻止后突然恢复访问
.github/skills/ca-policy-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill ca-policy-investigation -g -y
用于每周审查租户上下文记忆文件,对比最新SOC扫描报告提出ADD/MODIFY/FLAG变更建议。仅生成供人工审批的提案文档,绝不直接编辑文件或提交PR,确保人机协作安全。
review my context file review tenant context propose context updates what should I add to my context memory
.github/skills/context-memory-review/SKILL.md
npx skills add SCStelz/security-investigator --skill context-memory-review -g -y
通过Microsoft Graph API在Defender XDR中创建、部署和管理自定义检测规则。支持KQL适配、单条及批量部署、生命周期管理及验证,需使用PowerShell和特定权限。
用户需要部署或管理Microsoft Defender XDR的自定义检测规则 需要将Sentinel KQL查询转换为Defender XDR格式并执行部署
.github/skills/detection-authoring/SKILL.md
npx skills add SCStelz/security-investigator --skill detection-authoring -g -y
用于从Microsoft Sentinel数据生成交互式世界地图可视化,展示攻击来源、威胁地理分布或IP地理位置。支持通过KQL查询坐标数据,调用MCP工具渲染地图,并集成威胁情报增强功能以提供点击详情。
geomap world map geographic attack map show on map visualize locations attack origins latitude/longitude coordinates
.github/skills/geomap-visualization/SKILL.md
npx skills add SCStelz/security-investigator --skill geomap-visualization -g -y
用于从Microsoft Sentinel数据生成交互式热力图,展示按时间或实体聚合的活动模式。支持通过KQL查询获取数据,并集成威胁情报以增强分析能力。
创建热力图 可视化时间模式 显示活动网格 矩阵格式聚合数据 分析攻击模式 检查登录活动
.github/skills/heatmap-visualization/SKILL.md
npx skills add SCStelz/security-investigator --skill heatmap-visualization -g -y
用于分析蜜罐服务器安全性的技能,涵盖攻击模式、威胁情报关联、IP丰富化及漏洞评估。支持生成执行报告并追踪各阶段耗时,辅助识别新兴威胁。
honeypot investigation analyze honeypot honeypot security honeypot report
.github/skills/honeypot-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill honeypot-investigation -g -y
用于编写、创建和协助生成适用于 Microsoft Sentinel、Defender XDR 或 Azure Data Explorer 的生产级 KQL 查询。通过结合模式验证、官方文档及最佳实践,确保查询准确且高性能。
write KQL create KQL query help with KQL query [table] KQL for [scenario]
.github/skills/kql-query-authoring/SKILL.md
npx skills add SCStelz/security-investigator --skill kql-query-authoring -g -y
面向SOC日常操作的快速安全扫描技能,15分钟内并行执行7大领域(事件、身份、端点等)12项查询,生成威胁脉冲仪表盘及下钻建议。适用于新手入门或“从何入手”类咨询。
where do I start what can you do help me investigate
.github/skills/threat-pulse/SKILL.md
npx skills add SCStelz/security-investigator --skill threat-pulse -g -y
用于审计AI代理(Copilot Studio等)的安全态势。通过查询AgentsInfo表,评估代理库存、访问权限、MCP工具、知识源暴露、XPIA邮件风险及凭证泄露,全面识别安全风险与治理问题。
AI agent posture agent security audit Copilot Studio agents agent inventory agent access broadly accessible agents agent tools MCP tools on agents agent knowledge sources XPIA risk agent sprawl AI agent risk agent governance
.github/skills/ai-agent-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill ai-agent-posture -g -y
审计Entra ID应用注册和服务主体的安全态势,结合Graph API权限、所有权和凭证状态与KQL攻击链检测,评估风险并生成5维安全评分。
app registration posture service principal permissions dangerous app permissions app ownership app credential abuse SPN lateral movement app consent grant overprivileged apps cross-tenant SPN app registration kill chain app persistence credential add chain Graph API permissions audit
.github/skills/app-registration-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill app-registration-posture -g -y
用于分析 Entra ID 认证流,区分合法活动与令牌窃取。通过追踪 SessionId、检查 RequestSequence 和 IP 丰富数据,判断可疑登录是否涉及交互式 MFA,从而评估风险等级。
trace authentication SessionId analysis token reuse geographic anomaly impossible travel investigating suspicious sign-in locations
.github/skills/authentication-tracing/SKILL.md
npx skills add SCStelz/security-investigator --skill authentication-tracing -g -y
用于对Windows、macOS和Linux设备进行综合安全调查,分析Defender告警、登录模式、漏洞及合规性。支持Entra ID各类设备,提供快捷查询链以加速特定场景(如暴力破解、漏洞评估)的调查流程。
investigate computer investigate device investigate endpoint check machine device security endpoint investigation
.github/skills/computer-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill computer-investigation -g -y
分析DataSecurityEvents,追踪敏感信息类型(SIT)及敏感度标签的访问、DLP匹配和内部风险。支持EDM监控、标签变更跟踪及Copilot暴露分析,适用于大规模环境的数据安全审计与调查。
data security sensitive information type SIT access DLP events insider risk activity Purview data security sensitivity label label downgrade Copilot label exposure
.github/skills/data-security-analysis/SKILL.md
npx skills add SCStelz/security-investigator --skill data-security-analysis -g -y
基于Microsoft Defender for Office 365高级查询生成邮件威胁防护报告,评估安全态势。覆盖邮件流、威胁构成、钓鱼防护、认证、ZAP修复、Safe Links及附件分析等维度,支持Markdown和SVG输出。
email threat report email security posture phishing report MDO report Defender for Office 365 report ZAP effectiveness Safe Links report DMARC report spam report email volume report
.github/skills/email-threat-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill email-threat-posture -g -y
用于生成全面的漏洞与暴露管理报告,评估组织或单台设备的安全态势。涵盖CVE、配置合规、EoS软件、关键资产、攻击路径及证书状态,支持KQL查询与Markdown输出。
vulnerability report exposure report CVE assessment security posture vulnerability assessment exposure management patch status end of support security recommendations attack paths critical assets configuration compliance Defender device health security score TVM threat and vulnerability management
.github/skills/exposure-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill exposure-investigation -g -y
基于Microsoft Defender XDR高级狩猎,审计组织身份安全态势。覆盖账户清单、特权账号、闲置/已删账号、密码策略、风险分布及多提供商身份关联等维度,提供全面的安全评估与洞察。
identity posture identity security report account hygiene stale accounts privileged accounts password posture identity providers multi-provider identity identity sprawl service accounts deleted accounts with roles cross-IdP honeytoken sensitive accounts
.github/skills/identity-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill identity-posture -g -y
用于调查Microsoft Defender XDR或Sentinel中的安全事件。通过获取元数据、告警和资产,引导用户选择实体(用户、设备、IoC)进行深度调查,并支持多工作区选择和迭代分析。
investigate incident incident ID incident investigation analyze incident triage incident
.github/skills/incident-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill incident-investigation -g -y
用于调查IoC(IP、域名、URL、文件哈希)的安全技能。通过Microsoft Defender威胁情报和KQL查询,分析威胁关联、组织暴露面及受影响设备,支持快捷路径与完整深度调查模式。
investigate IP check domain IoC investigation threat intel is this malicious suspicious URL 包含需调查上下文的IP/域名/URL/哈希
.github/skills/ioc-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill ioc-investigation -g -y
用于监控和分析Microsoft Sentinel及Defender XDR环境中MCP服务器使用情况,涵盖Graph、Sentinel及Azure MCP的遥测数据、用户归因、敏感API检测及异常行为审计。
MCP usage MCP server monitoring MCP activity Graph MCP Sentinel MCP Azure MCP MCP audit tool usage monitoring MCP breakdown who is using MCP
.github/skills/mcp-usage-monitoring/SKILL.md
npx skills add SCStelz/security-investigator --skill mcp-usage-monitoring -g -y
生成MITRE ATT&CK覆盖报告,分析检测规则对攻击框架的覆盖情况。通过YAML驱动PowerShell采集Sentinel数据,识别覆盖缺口并提供优化建议,输出战术/技术级矩阵及综合覆盖率评分。
需要评估SIEM检测能力与MITRE框架对齐程度时 发现未标记规则需补充MITRE标签或识别覆盖盲区时 进行SOC运营优化以对齐特定威胁场景(如勒索软件)时
.github/skills/mitre-coverage-report/SKILL.md
npx skills add SCStelz/security-investigator --skill mitre-coverage-report -g -y
用于检测终端设备进程执行行为的渐进式漂移,识别偏离基线的异常活动。支持单设备深度调查和全舰队范围扫描,通过计算多维漂移评分及相关告警关联,发现隐蔽的缓慢渗透行为。
device drift endpoint drift process baseline device behavioral change
.github/skills/scope-drift-detection/device/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-device -g -y
用于检测 Entra ID 服务主体(SPN)的权限漂移和渐进式访问扩张。通过构建90天行为基线并与近期活动对比,计算加权漂移评分,关联安全日志以识别异常行为模式。
scope drift service principal drift SPN behavioral change automation account drift baseline deviation access expansion
.github/skills/scope-drift-detection/spn/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-spn -g -y
用于检测Entra ID用户账号的权限与行为漂移,识别渐进式越权。通过构建90天基线对比近期活动,计算多维度漂移分数,并关联安全告警、审计日志及云应用/邮件事件异常。
user drift user behavioral change user scope drift user baseline deviation user access expansion
.github/skills/scope-drift-detection/user/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-user -g -y
生成Azure Sentinel摄入分析报告,涵盖数据量、表级细分、层级分类、异常检测及优化建议。通过YAML驱动PowerShell收集KQL/REST数据至草稿,LLM渲染最终报告,支持深度分析与成本优化评估。
用户请求分析Azure Sentinel工作区的数据摄入情况 需要生成包含成本优化建议和异常检测的详细技术报告
.github/skills/sentinel-ingestion-report/SKILL.md
npx skills add SCStelz/security-investigator --skill sentinel-ingestion-report -g -y
用于根据调查数据或技能报告生成SVG数据可视化仪表板。支持基于YAML清单的结构化模式和基于上下文的自由自适应模式,提供KPI、图表等组件及暗色主题渲染。
generate SVG dashboard create a visual dashboard visualize this report SVG from the report visualize results create SVG chart SVG from this data
.github/skills/svg-dashboard/SKILL.md
npx skills add SCStelz/security-investigator --skill svg-dashboard -g -y
将威胁情报文章转化为可测试的狩猎活动。支持RSS/Atom订阅源批量处理或单篇文章模式,执行相关性筛选、KQL查询编写与调优,生成标准化战役文件及结构化结果,全程无Git副作用。
threat intel campaign ingest threat intelligence TI feed write hunts from this article threat intelligence blog build a hunting campaign
.github/skills/threat-intel-campaign/SKILL.md
npx skills add SCStelz/security-investigator --skill threat-intel-campaign -g -y
用于Entra ID用户账户的安全调查技能,分析登录异常、MFA状态、设备合规及审计日志。支持标准/快速/全面调查模式,提供内联、Markdown或HTML报告输出,并包含针对风险用户、账号泄露等场景的快捷查询链。
investigate user security investigation user investigation check user activity analyze sign-ins 提及UPN/email且上下文涉及调查
.github/skills/user-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill user-investigation -g -y

首页 - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-07-31 20:22
浙ICP备14020137号-1 $访客地图$