Agent Skills
› SCStelz/security-investigator
SCStelz/security-investigator
GitHub用于调查条件访问策略变更与登录失败(如53000、50074)的关联,区分合法故障排除与安全控制绕过。通过强制步骤分析策略状态转换和时间线,识别特权滥用或未经授权的修改。
安装全部 Skills
npx skills add SCStelz/security-investigator --all -g -y
集合内 Skills (27)
用于调查条件访问策略变更与登录失败(如53000、50074)的关联,区分合法故障排除与安全控制绕过。通过强制步骤分析策略状态转换和时间线,识别特权滥用或未经授权的修改。
Conditional Access
CA policy
device compliance
policy bypass
53000
50074
用户被阻止后突然恢复访问
npx skills add SCStelz/security-investigator --skill ca-policy-investigation -g -y
用于每周审查租户上下文记忆文件,对比最新SOC扫描报告提出ADD/MODIFY/FLAG变更建议。仅生成供人工审批的提案文档,绝不直接编辑文件或提交PR,确保人机协作安全。
review my context file
review tenant context
propose context updates
what should I add to my context memory
npx skills add SCStelz/security-investigator --skill context-memory-review -g -y
通过Microsoft Graph API在Defender XDR中创建、部署和管理自定义检测规则。支持KQL适配、单条及批量部署、生命周期管理及验证,需使用PowerShell和特定权限。
用户需要部署或管理Microsoft Defender XDR的自定义检测规则
需要将Sentinel KQL查询转换为Defender XDR格式并执行部署
npx skills add SCStelz/security-investigator --skill detection-authoring -g -y
用于从Microsoft Sentinel数据生成交互式世界地图可视化,展示攻击来源、威胁地理分布或IP地理位置。支持通过KQL查询坐标数据,调用MCP工具渲染地图,并集成威胁情报增强功能以提供点击详情。
geomap
world map
geographic
attack map
show on map
visualize locations
attack origins
latitude/longitude coordinates
npx skills add SCStelz/security-investigator --skill geomap-visualization -g -y
用于从Microsoft Sentinel数据生成交互式热力图,展示按时间或实体聚合的活动模式。支持通过KQL查询获取数据,并集成威胁情报以增强分析能力。
创建热力图
可视化时间模式
显示活动网格
矩阵格式聚合数据
分析攻击模式
检查登录活动
npx skills add SCStelz/security-investigator --skill heatmap-visualization -g -y
用于分析蜜罐服务器安全性的技能,涵盖攻击模式、威胁情报关联、IP丰富化及漏洞评估。支持生成执行报告并追踪各阶段耗时,辅助识别新兴威胁。
honeypot investigation
analyze honeypot
honeypot security
honeypot report
npx skills add SCStelz/security-investigator --skill honeypot-investigation -g -y
用于编写、创建和协助生成适用于 Microsoft Sentinel、Defender XDR 或 Azure Data Explorer 的生产级 KQL 查询。通过结合模式验证、官方文档及最佳实践,确保查询准确且高性能。
write KQL
create KQL query
help with KQL
query [table]
KQL for [scenario]
npx skills add SCStelz/security-investigator --skill kql-query-authoring -g -y
面向SOC日常操作的快速安全扫描技能,15分钟内并行执行7大领域(事件、身份、端点等)12项查询,生成威胁脉冲仪表盘及下钻建议。适用于新手入门或“从何入手”类咨询。
where do I start
what can you do
help me investigate
npx skills add SCStelz/security-investigator --skill threat-pulse -g -y
用于审计AI代理(Copilot Studio等)的安全态势。通过查询AgentsInfo表,评估代理库存、访问权限、MCP工具、知识源暴露、XPIA邮件风险及凭证泄露,全面识别安全风险与治理问题。
AI agent posture
agent security audit
Copilot Studio agents
agent inventory
agent access
broadly accessible agents
agent tools
MCP tools on agents
agent knowledge sources
XPIA risk
agent sprawl
AI agent risk
agent governance
npx skills add SCStelz/security-investigator --skill ai-agent-posture -g -y
审计Entra ID应用注册和服务主体的安全态势,结合Graph API权限、所有权和凭证状态与KQL攻击链检测,评估风险并生成5维安全评分。
app registration posture
service principal permissions
dangerous app permissions
app ownership
app credential abuse
SPN lateral movement
app consent grant
overprivileged apps
cross-tenant SPN
app registration kill chain
app persistence
credential add chain
Graph API permissions audit
npx skills add SCStelz/security-investigator --skill app-registration-posture -g -y
用于分析 Entra ID 认证流,区分合法活动与令牌窃取。通过追踪 SessionId、检查 RequestSequence 和 IP 丰富数据,判断可疑登录是否涉及交互式 MFA,从而评估风险等级。
trace authentication
SessionId analysis
token reuse
geographic anomaly
impossible travel
investigating suspicious sign-in locations
npx skills add SCStelz/security-investigator --skill authentication-tracing -g -y
用于对Windows、macOS和Linux设备进行综合安全调查,分析Defender告警、登录模式、漏洞及合规性。支持Entra ID各类设备,提供快捷查询链以加速特定场景(如暴力破解、漏洞评估)的调查流程。
investigate computer
investigate device
investigate endpoint
check machine
device security
endpoint investigation
npx skills add SCStelz/security-investigator --skill computer-investigation -g -y
分析DataSecurityEvents,追踪敏感信息类型(SIT)及敏感度标签的访问、DLP匹配和内部风险。支持EDM监控、标签变更跟踪及Copilot暴露分析,适用于大规模环境的数据安全审计与调查。
data security
sensitive information type
SIT access
DLP events
insider risk activity
Purview data security
sensitivity label
label downgrade
Copilot label exposure
npx skills add SCStelz/security-investigator --skill data-security-analysis -g -y
基于Microsoft Defender for Office 365高级查询生成邮件威胁防护报告,评估安全态势。覆盖邮件流、威胁构成、钓鱼防护、认证、ZAP修复、Safe Links及附件分析等维度,支持Markdown和SVG输出。
email threat report
email security posture
phishing report
MDO report
Defender for Office 365 report
ZAP effectiveness
Safe Links report
DMARC report
spam report
email volume report
npx skills add SCStelz/security-investigator --skill email-threat-posture -g -y
用于生成全面的漏洞与暴露管理报告,评估组织或单台设备的安全态势。涵盖CVE、配置合规、EoS软件、关键资产、攻击路径及证书状态,支持KQL查询与Markdown输出。
vulnerability report
exposure report
CVE assessment
security posture
vulnerability assessment
exposure management
patch status
end of support
security recommendations
attack paths
critical assets
configuration compliance
Defender device health
security score
TVM
threat and vulnerability management
npx skills add SCStelz/security-investigator --skill exposure-investigation -g -y
基于Microsoft Defender XDR高级狩猎,审计组织身份安全态势。覆盖账户清单、特权账号、闲置/已删账号、密码策略、风险分布及多提供商身份关联等维度,提供全面的安全评估与洞察。
identity posture
identity security report
account hygiene
stale accounts
privileged accounts
password posture
identity providers
multi-provider identity
identity sprawl
service accounts
deleted accounts with roles
cross-IdP
honeytoken
sensitive accounts
npx skills add SCStelz/security-investigator --skill identity-posture -g -y
用于调查Microsoft Defender XDR或Sentinel中的安全事件。通过获取元数据、告警和资产,引导用户选择实体(用户、设备、IoC)进行深度调查,并支持多工作区选择和迭代分析。
investigate incident
incident ID
incident investigation
analyze incident
triage incident
npx skills add SCStelz/security-investigator --skill incident-investigation -g -y
用于调查IoC(IP、域名、URL、文件哈希)的安全技能。通过Microsoft Defender威胁情报和KQL查询,分析威胁关联、组织暴露面及受影响设备,支持快捷路径与完整深度调查模式。
investigate IP
check domain
IoC investigation
threat intel
is this malicious
suspicious URL
包含需调查上下文的IP/域名/URL/哈希
npx skills add SCStelz/security-investigator --skill ioc-investigation -g -y
用于监控和分析Microsoft Sentinel及Defender XDR环境中MCP服务器使用情况,涵盖Graph、Sentinel及Azure MCP的遥测数据、用户归因、敏感API检测及异常行为审计。
MCP usage
MCP server monitoring
MCP activity
Graph MCP
Sentinel MCP
Azure MCP
MCP audit
tool usage monitoring
MCP breakdown
who is using MCP
npx skills add SCStelz/security-investigator --skill mcp-usage-monitoring -g -y
生成MITRE ATT&CK覆盖报告,分析检测规则对攻击框架的覆盖情况。通过YAML驱动PowerShell采集Sentinel数据,识别覆盖缺口并提供优化建议,输出战术/技术级矩阵及综合覆盖率评分。
需要评估SIEM检测能力与MITRE框架对齐程度时
发现未标记规则需补充MITRE标签或识别覆盖盲区时
进行SOC运营优化以对齐特定威胁场景(如勒索软件)时
npx skills add SCStelz/security-investigator --skill mitre-coverage-report -g -y
用于检测终端设备进程执行行为的渐进式漂移,识别偏离基线的异常活动。支持单设备深度调查和全舰队范围扫描,通过计算多维漂移评分及相关告警关联,发现隐蔽的缓慢渗透行为。
device drift
endpoint drift
process baseline
device behavioral change
npx skills add SCStelz/security-investigator --skill scope-drift-detection-device -g -y
用于检测 Entra ID 服务主体(SPN)的权限漂移和渐进式访问扩张。通过构建90天行为基线并与近期活动对比,计算加权漂移评分,关联安全日志以识别异常行为模式。
scope drift
service principal drift
SPN behavioral change
automation account drift
baseline deviation
access expansion
npx skills add SCStelz/security-investigator --skill scope-drift-detection-spn -g -y
用于检测Entra ID用户账号的权限与行为漂移,识别渐进式越权。通过构建90天基线对比近期活动,计算多维度漂移分数,并关联安全告警、审计日志及云应用/邮件事件异常。
user drift
user behavioral change
user scope drift
user baseline deviation
user access expansion
npx skills add SCStelz/security-investigator --skill scope-drift-detection-user -g -y
生成Azure Sentinel摄入分析报告,涵盖数据量、表级细分、层级分类、异常检测及优化建议。通过YAML驱动PowerShell收集KQL/REST数据至草稿,LLM渲染最终报告,支持深度分析与成本优化评估。
用户请求分析Azure Sentinel工作区的数据摄入情况
需要生成包含成本优化建议和异常检测的详细技术报告
npx skills add SCStelz/security-investigator --skill sentinel-ingestion-report -g -y
用于根据调查数据或技能报告生成SVG数据可视化仪表板。支持基于YAML清单的结构化模式和基于上下文的自由自适应模式,提供KPI、图表等组件及暗色主题渲染。
generate SVG dashboard
create a visual dashboard
visualize this report
SVG from the report
visualize results
create SVG chart
SVG from this data
npx skills add SCStelz/security-investigator --skill svg-dashboard -g -y
将威胁情报文章转化为可测试的狩猎活动。支持RSS/Atom订阅源批量处理或单篇文章模式,执行相关性筛选、KQL查询编写与调优,生成标准化战役文件及结构化结果,全程无Git副作用。
threat intel campaign
ingest threat intelligence
TI feed
write hunts from this article
threat intelligence blog
build a hunting campaign
npx skills add SCStelz/security-investigator --skill threat-intel-campaign -g -y
用于Entra ID用户账户的安全调查技能,分析登录异常、MFA状态、设备合规及审计日志。支持标准/快速/全面调查模式,提供内联、Markdown或HTML报告输出,并包含针对风险用户、账号泄露等场景的快捷查询链。
investigate user
security investigation
user investigation
check user activity
analyze sign-ins
提及UPN/email且上下文涉及调查
npx skills add SCStelz/security-investigator --skill user-investigation -g -y


