Agent Skills › SCStelz/security-investigator

SCStelz/security-investigator

GitHub

用于调查Azure Conditional Access策略变更与登录失败的关联,识别合法排障、安全绕过及权限滥用行为。

27 个 Skill 231

安装全部 Skills

npx skills add SCStelz/security-investigator --all -g -y
更多选项

预览集合内 Skills

npx skills add SCStelz/security-investigator --list

集合内 Skills (27)

用于调查Azure Conditional Access策略变更与登录失败的关联,识别合法排障、安全绕过及权限滥用行为。
Conditional Access CA policy sign-in failures policy bypass error codes 53000, 50074
.github/skills/ca-policy-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill ca-policy-investigation -g -y
定期审查租户上下文记忆文件,对比最新安全扫描报告,生成仅提议的变更文档供人工审核。该技能严格只读,不修改原文件或提交PR,确保上下文数据的准确性与安全性。
review my context file review tenant context propose context updates what should I add to my context memory
.github/skills/context-memory-review/SKILL.md
npx skills add SCStelz/security-investigator --skill context-memory-review -g -y
用于通过 Microsoft Graph API 在 Defender XDR 中创建、部署和管理自定义检测规则。支持 KQL 查询适配、单条及批量部署、生命周期管理及验证,依赖 PowerShell 和特定权限。
部署自定义检测规则 管理 Defender XDR 检测规则 KQL 查询适配与发布
.github/skills/detection-authoring/SKILL.md
npx skills add SCStelz/security-investigator --skill detection-authoring -g -y
基于Microsoft Sentinel数据生成交互式世界地图可视化,展示攻击来源、威胁地理分布及IP定位。支持通过KQL查询坐标数据并渲染为带有威胁情报增强的动态地图。
geomap world map geographic attack map show on map visualize locations attack origins latitude/longitude
.github/skills/geomap-visualization/SKILL.md
npx skills add SCStelz/security-investigator --skill geomap-visualization -g -y
基于 Microsoft Sentinel 数据生成交互式热力图,用于可视化时间模式、活动网格及聚合数据矩阵,辅助识别异常和攻击模式。
创建热力图 可视化时间模式 显示活动网格 分析攻击模式 查看登录活动分布
.github/skills/heatmap-visualization/SKILL.md
npx skills add SCStelz/security-investigator --skill heatmap-visualization -g -y
用于对蜜罐服务器进行安全分析、攻击模式识别、威胁情报关联及漏洞评估,并生成执行报告。
honeypot investigation analyze honeypot honeypot security honeypot report
.github/skills/honeypot-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill honeypot-investigation -g -y
用于编写、创建和辅助生成适用于 Microsoft Sentinel、Defender XDR 及 Azure Data Explorer 的生产级 KQL 查询。通过结合模式验证、官方文档和社区示例,确保查询的正确性与性能。
用户请求编写或创建 KQL 查询 涉及 Microsoft Sentinel 或 Defender XDR 的数据分析场景 提到 'write KQL', 'create KQL query' 等关键词
.github/skills/kql-query-authoring/SKILL.md
npx skills add SCStelz/security-investigator --skill kql-query-authoring -g -y
Threat Pulse 是面向 SOC 日常运营和新手入门的快速安全扫描技能。它在 15 分钟内并行执行跨 7 个领域的 12 项查询,生成包含优先级发现和下钻建议的威胁脉冲仪表板,帮助用户快速掌握安全态势并定位问题。
用户询问如何开始或系统能做什么 需要每日安全运营概览 请求进行广泛的安全态势扫描
.github/skills/threat-pulse/SKILL.md
npx skills add SCStelz/security-investigator --skill threat-pulse -g -y
审计AI代理(Copilot Studio等)的安全态势,评估库存、访问权限、工具暴露、凭证泄露及XPIA风险。通过查询AgentsInfo表生成综合安全报告,覆盖治理与 sprawl 分析。
AI agent posture agent security audit Copilot Studio agents agent inventory agent access broadly accessible agents agent tools MCP tools on agents agent knowledge sources XPIA risk agent sprawl AI agent risk agent governance
.github/skills/ai-agent-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill ai-agent-posture -g -y
审计Entra ID应用注册和服务主体安全态势,结合Graph API库存与KQL攻击链检测,评估权限、所有者风险、凭证卫生及跨租户暴露,生成风险评分。
app registration posture service principal permissions dangerous app permissions app ownership app credential abuse SPN lateral movement app consent grant overprivileged apps cross-tenant SPN app registration kill chain app persistence credential add chain Graph API permissions audit
.github/skills/app-registration-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill app-registration-posture -g -y
用于分析 Entra ID 认证流,通过 SessionId 和 IP 数据区分合法活动与凭证窃取,评估地理异常及 MFA 交互状态。
trace authentication SessionId analysis token reuse geographic anomaly impossible travel
.github/skills/authentication-tracing/SKILL.md
npx skills add SCStelz/security-investigator --skill authentication-tracing -g -y
用于对Windows/macOS/Linux设备进行安全调查,分析Defender告警、漏洞、合规性及网络活动。适用于排查恶意软件、可疑行为及合规审查,支持多种输出模式与快捷查询链。
investigate computer investigate device investigate endpoint check machine device security endpoint investigation
.github/skills/computer-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill computer-investigation -g -y
分析Microsoft Purview DLP及内部风险事件,查询DataSecurityEvents表,提供敏感信息类型(SIT)访问、敏感度标签变更、Copilot数据暴露等安全事件的KQL分析与报告生成。
data security sensitive information type SIT access DLP events insider risk activity Purview data security sensitivity label label downgrade Copilot label exposure
.github/skills/data-security-analysis/SKILL.md
npx skills add SCStelz/security-investigator --skill data-security-analysis -g -y
基于Microsoft Defender for Office 365高级狩猎数据,生成邮件威胁防护报告。涵盖邮件流、钓鱼检测、身份验证、ZAP补救及附件分析等维度,评估组织邮件安全态势并提供C级可见性。
email threat report email security posture phishing report MDO report Defender for Office 365 report ZAP effectiveness Safe Links report DMARC report spam report email volume report
.github/skills/email-threat-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill email-threat-posture -g -y
生成漏洞与暴露管理报告,评估安全态势。涵盖CVE、配置合规、终止支持软件、关键资产及攻击路径分析。支持组织级或单设备范围查询,输出Markdown报告。
vulnerability report exposure report CVE assessment security posture attack paths
.github/skills/exposure-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill exposure-investigation -g -y
审计组织身份安全态势,涵盖账户清单、特权账号、闲置/删除账号清理、密码策略、风险分布及多提供商身份关联分析。
identity posture identity security report account hygiene stale accounts privileged accounts password posture identity providers multi-provider identity identity sprawl service accounts deleted accounts with roles cross-IdP honeytoken sensitive accounts
.github/skills/identity-posture/SKILL.md
npx skills add SCStelz/security-investigator --skill identity-posture -g -y
用于调查Microsoft Defender XDR或Sentinel安全事件。通过检索元数据、警报和资产,引导用户选择实体进行深度分析(如用户、设备、IoC),提供全面的事件调查工作流。
investigate incident incident ID incident investigation analyze incident triage incident
.github/skills/incident-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill incident-investigation -g -y
用于调查IP、域名、URL或文件哈希等威胁指标,结合Microsoft Defender情报进行深度分析,识别恶意行为并评估组织资产受影响情况。
investigate IP check domain IoC investigation threat intel is this malicious suspicious URL
.github/skills/ioc-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill ioc-investigation -g -y
用于监控和审计 Microsoft Sentinel 及 Defender XDR 环境中 MCP 服务器使用情况,分析遥测数据、用户归属、敏感 API 访问及安全风险评估。
MCP usage MCP server monitoring MCP activity Graph MCP Sentinel MCP Azure MCP MCP audit tool usage monitoring MCP breakdown who is using MCP
.github/skills/mcp-usage-monitoring/SKILL.md
npx skills add SCStelz/security-investigator --skill mcp-usage-monitoring -g -y
生成MITRE ATT&CK检测覆盖率报告,分析规则映射、识别覆盖缺口并提供优化建议。通过PowerShell脚本收集Sentinel数据,LLM渲染最终报告。
需要评估安全检测规则对MITRE框架的覆盖情况 识别未标记或无效的Analytic Rules并获取修复建议 生成包含Tactic/Technique矩阵及覆盖评分的综合安全报告
.github/skills/mitre-coverage-report/SKILL.md
npx skills add SCStelz/security-investigator --skill mitre-coverage-report -g -y
检测终端设备进程行为基线漂移,识别渐进式异常扩展。通过计算五维漂移评分并关联安全告警,支持单设备深入排查与全fleet范围监控,适用于隐蔽性慢速攻击检测。
device drift endpoint drift process baseline deviation investigate device behavioral change
.github/skills/scope-drift-detection/device/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-device -g -y
检测 Entra ID 服务主体范围漂移,通过构建90天行为基线与近期活动对比,计算加权漂移分数,识别权限或行为的渐进式异常扩张。
scope drift service principal drift SPN behavioral change automation account drift baseline deviation access expansion
.github/skills/scope-drift-detection/spn/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-spn -g -y
用于检测 Entra ID 用户账号的范围漂移,通过对比90天基线与近期行为,计算加权漂移分数并关联安全日志,识别渐进式权限扩张或异常行为。
用户范围漂移 用户行为变化 用户基线偏差 访问权限扩展
.github/skills/scope-drift-detection/user/SKILL.md
npx skills add SCStelz/security-investigator --skill scope-drift-detection-user -g -y
生成Azure Sentinel摄入分析报告,涵盖数据量、表级分类、异常检测及优化建议。通过YAML驱动PowerShell脚本自动采集KQL和API数据,由LLM渲染最终报告,辅助成本分析与安全策略优化。
需要分析Azure Sentinel工作区的数据摄入量和成本结构 检测数据摄入异常或优化数据分层策略 评估检测规则覆盖率和健康状态
.github/skills/sentinel-ingestion-report/SKILL.md
npx skills add SCStelz/security-investigator --skill sentinel-ingestion-report -g -y
根据技能报告或调查数据生成SVG可视化仪表盘。支持基于YAML清单的结构化模式和基于上下文数据的自由自适应模式,提供多种图表组件及暗色主题渲染。
generate SVG dashboard create a visual dashboard visualize this report SVG from the report visualize results create SVG chart SVG from this data
.github/skills/svg-dashboard/SKILL.md
npx skills add SCStelz/security-investigator --skill svg-dashboard -g -y
将威胁情报文章转化为可测试的狩猎活动。解析RSS/Atom源,评估相关性,编写、测试并优化KQL查询,生成活动文件及结构化结果,不涉及Git操作。
threat intel campaign ingest threat intelligence TI feed write hunts from this article threat intelligence blog build a hunting campaign
.github/skills/threat-intel-campaign/SKILL.md
npx skills add SCStelz/security-investigator --skill threat-intel-campaign -g -y
用于Entra ID用户账户的安全调查,分析登录异常、MFA状态、设备合规及审计日志,支持生成多种格式报告。
investigate user security investigation user investigation check user activity analyze sign-ins
.github/skills/user-investigation/SKILL.md
npx skills add SCStelz/security-investigator --skill user-investigation -g -y

首页 - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-07 13:10
浙ICP备14020137号-1 $访客地图$