Agent Skills › SCStelz/security-investigator

SCStelz/security-investigator

GitHub

用于调查条件访问策略变更与登录失败关联的技能,检测合法故障排除、安全控制绕过及权限滥用。

28 个 Skill 247

安装全部 Skills

npx skills add SCStelz/security-investigator --all -g -y
更多选项

预览集合内 Skills

npx skills add SCStelz/security-investigator --list

集合内 Skills (28)

用于调查条件访问策略变更与登录失败关联的技能,检测合法故障排除、安全控制绕过及权限滥用。
Conditional Access policy changes investigation sign-in failures related to CA policies suspected policy bypass or manipulation
.github/skills/ca-policy-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill ca-policy-investigation -g -y
定期审查租户上下文记忆文件,比对扫描报告与发现日志,生成仅建议的变更文档供人工审批。该技能严格只读,不修改任何文件或提交代码,旨在通过人类反馈循环确保上下文数据的准确性。
review my context file review tenant context propose context updates compact findings to memory what should I add to my context memory
.github/skills/context-memory-review/SKILL.md
npx skills add SCStelz/security-investigator --skill context-memory-review -g -y
通过 Graph API 在 Microsoft Defender XDR 中创建、部署和管理自定义检测规则。涵盖 KQL 适配、单条及批量部署、生命周期管理及验证,解决权限与格式限制问题。
需要部署自定义检测规则到 Defender XDR 将 Sentinel KQL 转换为 Defender 自定义检测格式 管理 Defender XDR 检测规则的生命周期(增删改查)
.github/skills/detection-authoring/SKILL.md
npx skills add SCStelz/security-investigator --skill detection-authoring -g -y
用于从Microsoft Sentinel数据生成交互式世界地图可视化,展示攻击来源、地理分布及基于IP坐标的安全威胁数据。
创建地理地图 可视化攻击来源 显示位置数据 IP地理位置分析
.github/skills/geomap-visualization/SKILL.md
npx skills add SCStelz/security-investigator --skill geomap-visualization -g -y
基于Microsoft Sentinel数据生成交互式热力图,用于可视化登录活动、攻击模式及事件分布的时间聚合规律。
创建热力图 可视化时间模式 显示活动网格 分析登录或攻击行为
.github/skills/heatmap-visualization/SKILL.md
npx skills add SCStelz/security-investigator --skill heatmap-visualization -g -y
用于对蜜罐服务器进行安全分析、攻击模式调查、威胁情报关联及漏洞评估,并生成执行报告。
honeypot investigation analyze honeypot honeypot security honeypot report
.github/skills/honeypot-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill honeypot-investigation -g -y
用于编写和生成适用于Microsoft Sentinel、Defender XDR及Azure Data Explorer的KQL查询。通过结合Schema验证、官方文档和社区示例,确保生成的查询生产就绪且性能优化。
用户请求编写或创建KQL查询 需要针对特定数据场景生成分析查询 涉及Microsoft Sentinel或Defender XDR的数据查询任务
.github/skills/kql-query-authoring/SKILL.md
npx skills add SCStelz/security-investigator --skill kql-query-authoring -g -y
面向安全运营中心(SOC)的每日快速扫描技能,覆盖7大领域并行执行12项查询,生成威胁仪表盘并提供深入调查建议。适用于新手入门或日常安全态势感知场景。
用户询问如何开始使用或系统能做什么 需要快速进行多维度安全扫描和态势评估 获取每日安全概览和优先处理建议
.github/skills/threat-pulse/SKILL.md
npx skills add SCStelz/security-investigator --skill threat-pulse -g -y
用于报告和分析 Microsoft AI Agent(如 Copilot Studio、Agent 365)的运行时活动,包括用户行为、工具调用、Token 消耗及安全拦截(Jailbreak/XPIA),支持多数据源自动检测与租户/单用户级范围查询。
agent activity AI agent usage who is using agents jailbreak activity prompt injection activity
.github/skills/ai-agent-activity/SKILL.md
npx skills add SCStelz/security-investigator --skill ai-agent-activity -g -y
审计AI代理(Copilot、Foundry等)的安全态势,涵盖资产盘点、访问权限、MCP工具、凭证暴露及XPIA风险。通过Advanced Hunting查询AgentsInfo表评估攻击面,支持治理与休眠代理检测。
AI agent posture agent security audit Copilot Studio agents agent inventory broadly accessible agents agent tools MCP tools on agents XPIA risk agent sprawl agent governance agent identity dormant agents ownerless agents investigating agent configs access posture tool permissions credential exposure Entra agent identities
.github/skills/ai-agent-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill ai-agent-posture -g -y
审计Entra ID应用注册和服务主体的安全态势,结合Graph API状态与KQL攻击链检测,评估权限、所有者风险、凭证卫生及跨租户暴露。
app registration posture service principal permissions dangerous app permissions
.github/skills/app-registration-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill app-registration-posture -g -y
用于追踪身份验证流程、分析会话ID链及令牌复用,通过取证手段区分合法活动与凭证窃取。适用于地理异常或可疑登录调查。
trace authentication SessionId analysis token reuse geographic anomaly
.github/skills/authentication-tracing/SKILL.md
npx skills add SCStelz/security-investigator --skill authentication-tracing -g -y
用于对 Windows/macOS/Linux 设备进行安全调查,分析 Defender 告警、漏洞、合规性及登录行为等。适用于排查恶意软件、可疑活动或合规审查。
investigate computer investigate device investigate endpoint check machine device security endpoint investigation
.github/skills/computer-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill computer-investigation -g -y
分析Microsoft Purview DLP及数据安全事件,查询DataSecurityEvents表,评估敏感信息类型访问、标签变更及内部风险,支持大规模环境下的用户下钻与风险排名。
data security DLP events insider risk activity sensitivity label SIT access
.github/skills/data-security-analysis/SKILL.md
npx skills add SCStelz/security-investigator --skill data-security-analysis -g -y
基于Microsoft Defender for Office 365遥测数据生成邮件威胁防护报告,评估组织邮件安全态势,涵盖流量、威胁检测、认证及ZAP修复等维度。
email threat report email security posture phishing report MDO report
.github/skills/email-threat-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill email-threat-posture -g -y
生成漏洞与暴露管理报告,评估组织或设备的安全态势。涵盖CVE、配置合规、终止支持软件、关键资产、攻击路径及证书状态,提供全面的安全建议。
vulnerability report security posture CVE assessment
.github/skills/exposure-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill exposure-investigation -g -y
审计组织身份安全态势,覆盖账户清单、特权账号、闲置/删除账号、密码策略及多身份提供商关联分析。
identity posture stale accounts privileged accounts password posture
.github/skills/identity-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill identity-posture -g -y
用于调查 Microsoft Defender XDR 和 Sentinel 中的安全事件。通过检索元数据、警报及资产,对用户选定的实体(用户、设备、IoC)进行深度调查,最终输出包含判定门控的调查报告。
investigate incident incident ID incident investigation analyze incident triage incident
.github/skills/incident-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill incident-investigation -g -y
用于调查 IoC(如 IP、域名、URL、文件哈希)的安全技能,结合 Microsoft Defender 威胁情报与 KQL 查询进行关联分析与资产暴露评估。
investigate IP check domain IoC investigation threat intel is this malicious suspicious URL
.github/skills/ioc-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill ioc-investigation -g -y
监控审计 Microsoft Sentinel 和 Defender XDR 环境中 MCP 服务器的使用情况,分析遥测数据、用户行为及安全风险。
MCP usage MCP server monitoring MCP activity MCP audit tool usage monitoring who is using MCP
.github/skills/mcp-usage-monitoring/SKILL.md
npx skills add SCStelz/security-investigator --skill mcp-usage-monitoring -g -y
生成MITRE ATT&CK检测覆盖报告,自动采集规则与告警数据,映射战术技术,识别覆盖缺口并提供优化建议。
需要分析安全检测规则对MITRE框架的覆盖情况 评估SIEM/SOC检测能力并生成合规或优化报告
.github/skills/mitre-coverage-report/SKILL.md
npx skills add SCStelz/security-investigator --skill mitre-coverage-report -g -y
用于检测终端设备进程执行行为的范围漂移,通过构建基线并计算多维漂移分数,识别渐进式异常活动。
device drift endpoint drift process baseline deviation
.github/skills/scope-drift-detection/device/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-device -g -y
检测服务主体范围漂移,通过对比90天基线与近期活动,计算加权漂移得分并关联安全日志,识别权限或行为的渐进式异常扩张。
scope drift service principal drift SPN behavioral change automation account drift baseline deviation access expansion
.github/skills/scope-drift-detection/spn/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-spn -g -y
用于检测 Entra ID 用户账户的权限与行为范围漂移。通过建立90天基线并对比近期活动,计算加权漂移分数,关联安全警报、审计日志及云应用事件,识别渐进式越权或异常行为。
用户范围漂移检测 用户行为基线偏离分析 账号权限逐渐扩大调查 用户访问范围异常排查
.github/skills/scope-drift-detection/user/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-user -g -y
生成Azure Sentinel ingestion分析报告,涵盖数据量、表级分解、异常检测及优化建议。
需要分析Sentinel工作区的数据摄入量和成本 检测数据摄入异常或规则健康状态 评估分层迁移候选项与许可证效益
.github/skills/sentinel-ingestion-report/SKILL.md
npx skills add SCStelz/security-investigator --skill sentinel-ingestion-report -g -y
用于根据技能报告或调查数据生成SVG数据可视化仪表板。支持基于YAML清单的结构化模式和自由形式的自适应可视化,包含多种图表组件。
generate SVG dashboard create a visual dashboard visualize this report SVG from the report visualize results create SVG chart SVG from this data
.github/skills/svg-dashboard/SKILL.md
npx skills add SCStelz/security-investigator --skill svg-dashboard -g -y
将威胁情报文章转化为可测试的狩猎活动,包括解析、过滤、编写和测试KQL查询。
threat intel campaign ingest threat intelligence TI feed
.github/skills/threat-intel-campaign/SKILL.md
npx skills add SCStelz/security-investigator --skill threat-intel-campaign -g -y
用于调查 Entra ID 用户账户的安全问题、可疑活动或合规审查。分析登录异常、MFA 状态、设备合规性及审计日志,并生成报告。
investigate user security investigation user investigation check user activity analyze sign-ins
.github/skills/user-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill user-investigation -g -y

首页 - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-09-23 07:22
浙ICP备14020137号-1