SCStelz

29 mods across 1 repository, 243 stars between them.

SCStelz/security-investigator

Instructions file GitHub Copilot

Instructions for SCStelz/security-investigator, covering github copilot - security investigation integration, 📑 table of contents, ⚠️ critical workflow rules - read first ⚠️, 🔧 environment configuration and prerequisites.

243 2d ago A 22,159 tokens original MIT

ai-agent-activity

02

SCStelz/security-investigator

Skill Claude CodeCodex

Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield jailbreak/XPIA verdicts. Triggers: "agent activity", "AI agent usage", "who is using agents", "agent runtime", "agent…

243 2d ago A 194 tokens original MIT

ai-agent-posture

03

SCStelz/security-investigator

Skill Claude CodeCodex

Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents. Triggers on "AI agent posture", "agent security audit", "Copilot Studio agents", "agent inventory", "broadly accessible agents", "agent tools", "MCP tools on agents", "XPIA risk"…

243 2d ago A 222 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Audit Entra ID app registration and service principal security posture. Triggers on keywords like "app registration posture", "service principal permissions", "dangerous app permissions", "app ownership", "app credential abuse", "SPN lateral movement", "app consent grant", "overprivileged apps", "cross-tenant SPN"…

243 2d ago A 176 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins. Triggers on keywords like "trace authentication", "trace back to interactive MFA", "SessionId analysis", "token reuse", "geographic anomaly"…

243 2d ago A 97 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy bypass/manipulation. Triggers on keywords like "Conditional Access", "CA policy", "device compliance", "policy bypass", "53000", "50074", or when…

243 2d ago A 104 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to investigate a computer, device, endpoint, or machine for security issues, suspicious activity, malware, or compliance review. Triggers on keywords like "investigate computer", "investigate device", "investigate endpoint", "check machine", "device security", "endpoint investigation", or…

243 2d ago A 126 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Weekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g. Threat Pulse) and the Mission Control findings log. Surfaces candidate ADD / MODIFY / FLAG changes to the context file as a propose-only review document for human approval — it NEVER edits the context file…

243 2d ago A 106 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Analyze data security events, sensitive information type (SIT) access, sensitivity label access, DLP matches, or Purview insider risk activity. Triggers on keywords like "data security", "sensitive information type", "SIT access", "DLP events", "DataSecurityEvents", "EDM access", "credit card access", "insider risk…

243 2d ago A 179 tokens original MIT

detection-authoring

10

SCStelz/security-investigator

Skill Claude CodeCodex

Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules). Covers query adaptation from Sentinel KQL to custom detection format, deployment via PowerShell (Invoke-MgGraphRequest), manifest-driven batch deployment, and lifecycle…

243 2d ago A 85 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Generate email threat protection reports and assess email security posture. Triggers on keywords like "email threat report", "email security posture", "phishing report", "MDO report", "Defender for Office 365 report", "ZAP effectiveness", "Safe Links report", "DMARC report", "spam report", "email volume report".…

243 2d ago A 156 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to generate a vulnerability and exposure management report, assess security posture, or review CVEs, security configurations, and attack paths. Triggers on keywords like "vulnerability report", "exposure report", "CVE assessment", "security posture", "vulnerability assessment", "exposure…

243 2d ago A 194 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to create geographic maps, visualize attack origins on a world map, show location-based data, or display IP geolocation. Triggers on keywords like "geomap", "world map", "geographic", "attack map", "show on map", "visualize locations", "attack origins", or when analyzing data with…

243 2d ago A 80 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to create heatmaps, visualize patterns over time, show activity grids, or display aggregated data in a matrix format. Triggers on keywords like "heatmap", "show heatmap", "visualize patterns", "activity grid", "time-based visualization", or when analyzing attack patterns, sign-in activity, or…

243 2d ago A 79 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to analyze, investigate, or report on honeypot server security. Triggers on keywords like "honeypot investigation", "analyze honeypot", "honeypot security", "honeypot report", or when a server name is mentioned with honeypot analysis context. This skill provides comprehensive security…

243 2d ago A 94 tokens original MIT

identity-posture

16

SCStelz/security-investigator

Skill Claude CodeCodex

Audit identity security posture across the organization. Triggers on keywords like "identity posture", "identity security report", "account hygiene", "stale accounts", "privileged accounts", "password posture", "identity providers", "multi-provider identity", "identity sprawl", "service accounts", "deleted accounts…

243 2d ago A 150 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. Triggers on keywords like "investigate incident", "incident ID", "incident investigation", "analyze incident", "triage incident", or when an incident number/ID is mentioned with investigation context.…

243 2d ago A 97 tokens original MIT

ioc-investigation

18

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to investigate an Indicator of Compromise (IoC) such as an IP address, DNS domain, URL, or file hash. Triggers on keywords like "investigate IP", "check domain", "IoC investigation", "threat intel", "is this malicious", "suspicious URL", or when an IP/domain/URL/hash is mentioned with…

243 2d ago A 118 tokens original MIT

kql-query-authoring

19

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer. Triggers on keywords like "write KQL", "create KQL query", "help with KQL", "query [table]", "KQL for [scenario]", or when a user requests queries for specific data…

243 2d ago A 108 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to monitor, audit, or analyze MCP (Model Context Protocol) server usage in the environment. Triggers on keywords like "MCP usage", "MCP server monitoring", "MCP activity", "Graph MCP", "Sentinel MCP", "Azure MCP", "MCP audit", "tool usage monitoring", "MCP breakdown", "who is using MCP", or…

243 2d ago A 159 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

MITRE ATT&CK Coverage Report — YAML-driven PowerShell pipeline gathers analytic rule MITRE tags, custom detection techniques, SOC Optimization recommendations, and alert/incident operational data via az rest/az monitor/Graph API, writes a deterministic scratchpad, LLM renders the report. Covers tactic-level coverage…

243 2d ago A 115 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to detect scope drift, behavioral expansion, or process baseline deviation on devices or endpoints. Triggers on keywords like "device drift", "device process drift", "endpoint drift", "process baseline", "device behavioral change", or when investigating whether a device has gradually expanded…

243 2d ago A 148 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to detect scope drift, behavioral expansion, or gradual privilege/access creep in service principals or automation accounts. Triggers on keywords like "scope drift", "service principal drift", "SPN behavioral change", "automation account drift", "baseline deviation", "access expansion", or…

243 2d ago A 127 tokens original MIT

SCStelz/security-investigator

Skill Claude CodeCodex

Use this skill when asked to detect scope drift, behavioral expansion, or gradual privilege/access creep in user accounts. Triggers on keywords like "user drift", "user behavioral change", "user scope drift", "user baseline deviation", "user access expansion", or when investigating whether a user account has gradually…

243 2d ago A 152 tokens original MIT