Skip to main content
Manus에서 모든 스킬 실행
원클릭으로
stefanpems
GitHub 제작자 프로필

stefanpems

1개 GitHub 저장소에서 수집된 13개 skills를 저장소 단위로 보여줍니다.

수집된 skills
13
저장소
1
업데이트
2026-06-04
저장소 지도

skills가 있는 위치

수집된 skill 수가 많은 주요 저장소와 이 제작자 카탈로그 내 비중, 직업 분포를 보여줍니다.

저장소 탐색

저장소와 대표 skills

incident-comment
정보 보안 분석가

Use this skill when asked to write, post, or add a comment to a Microsoft Sentinel incident. Accepts plain text, Markdown, or HTML content as input. Plain text is posted as-is; Markdown is converted to HTML optimized for the narrow Activities panel; HTML is adapted for single-column display. ALL input content is preserved in full — no summarization or truncation — unless the user explicitly requests it. Triggers on: "write comment", "add comment", "post comment", "scrivi commento", "aggiungi commento", "commenta incidente", "comment on incident", "post to incident", "annotate incident".

2026-06-04
computer-investigation
정보 보안 분석가

Computer/device security investigation skill for environments with Azure Monitor MCP (Log Analytics workspace queries) and Azure CLI access — currently without Sentinel Data Lake MCP, Sentinel Triage MCP, or Microsoft Graph MCP (these cannot be connected to Azure SRE Agent yet; direct API access to Sentinel Data Lake and Microsoft Graph not yet implemented). Device data from Entra ID is collected via Azure CLI (`az rest` for Graph API) or KQL fallback queries from DeviceInfo/SigninLogs. KQL queries run against Log Analytics tables through the Azure Monitor MCP tool. TVM tables (software inventory, vulnerabilities) are NOT available through Log Analytics.

2026-06-03
identity-posture
정보 보안 분석가

Audit identity security posture across the organization. Triggers on keywords like "identity posture", "identity security report", "account hygiene", "stale accounts", "privileged accounts", "password posture", "identity providers", "identity sprawl", "service accounts", "deleted accounts with roles", "honeytoken", "sensitive accounts", "MFA coverage", "risky users". Collects data from Microsoft Graph API (user inventory, roles, PIM, risk, MFA) and Log Analytics KQL (IdentityInfo UAC flags, MDI tags, IdentityLogonEvents, SigninLogs). Produces a posture assessment covering account inventory, privileged account audit, stale/deleted account hygiene, password posture, MFA coverage, risk distribution, MDI tag analysis, and department-level insights. Inline chat or markdown output.

2026-06-03
incident-investigation
정보 보안 분석가

Use this skill when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. Triggers on keywords like "investigate incident", "incident ID", "incident investigation", "analyze incident", "triage incident", or when an incident number/ID is mentioned with investigation context. This skill provides comprehensive incident analysis including metadata retrieval, alert listing, asset enumeration, evidence filtering, and deep entity investigation using KQL queries via Azure Monitor MCP and specialized sub-skills. Environment: Azure Monitor MCP + Azure CLI — currently without Sentinel Data Lake MCP, Sentinel Triage MCP, or Microsoft Graph MCP (not yet connectable to Azure SRE Agent).

2026-06-03
incident-listing
정보 보안 분석가

Use this skill when the user asks to list, show, or enumerate recent security incidents. Ensures the KQL query against SecurityIncident is aligned with the Microsoft Defender XDR portal view (correct time filter, incident IDs, and phantom incident exclusion).

2026-06-03
incident-statistics
정보 보안 분석가

Use this skill when the user asks for incident statistics, incident metrics, incident reports, SOC dashboard data, MTTA/MTTR analysis, incident distribution, or any quantitative analysis of security incidents over a given time period. ALSO use this skill when the user asks for a high-level view, overview, summary, or status of SOC operations, CIRT/CSIRT activities, security operations, or the security posture in general. These requests are equivalent to asking for incident statistics because security incidents are the primary measurable output of SOC/CIRT/CSIRT work. Triggers on keywords like: "incident statistics", "incident report", "incident metrics", "how many incidents", "MTTA", "MTTR", "incident trend", "SOC metrics", "incident summary", "incident dashboard", "affected users", "affected devices", "incident assignees", "MITRE coverage", "true positive incidents", "SOC overview", "SOC status", "SOC activity", "CIRT overview", "CSIRT overview", "CIRT status", "CSIRT status", "security overview", "security

2026-06-03
ioc-investigation
정보 보안 분석가

IoC (Indicator of Compromise) investigation skill for environments with Azure Monitor MCP (Log Analytics workspace queries) and Azure CLI access — currently without Sentinel Data Lake MCP, Sentinel Triage MCP, or Microsoft Graph MCP (not yet connectable to Azure SRE Agent; direct API access to Sentinel Data Lake and Microsoft Graph not yet implemented). KQL queries run against Log Analytics tables through the Azure Monitor MCP tool. MDE API calls (custom IOC list, TVM) are executed via RunAzCliReadCommands (az rest). 3rd-party IP enrichment is provided by enrich_ips.py (ipinfo.io, vpnapi.io, AbuseIPDB, Shodan).

2026-06-03
mcp-usage-monitoring
정보 보안 분석가

Use this skill when asked to monitor, audit, or analyze MCP (Model Context Protocol) server usage in the environment. Triggers on keywords like "MCP usage", "MCP server monitoring", "MCP activity", "Graph MCP", "Sentinel MCP", "Azure MCP", "MCP audit", "tool usage monitoring", "MCP breakdown", "who is using MCP", or when investigating MCP user activity, Graph API calls from MCP servers, or workspace query governance. This skill provides comprehensive MCP server telemetry analysis across Graph MCP, Sentinel MCP, and Azure MCP servers including usage trends, endpoint access patterns, user attribution, cross-server user analysis, sensitive API detection, workspace query governance, and security risk assessment with inline and markdown file reporting.

2026-06-03
이 저장소에서 수집된 skills 13개 중 상위 8개를 표시합니다.
저장소 1개 중 1개 표시
모든 저장소를 표시했습니다