一键导入
defender-endpoint
Deep expertise in Defender Endpoint operations with deterministic runbooks, fail-fast context validation, and redacted output requirements.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Deep expertise in Defender Endpoint operations with deterministic runbooks, fail-fast context validation, and redacted output requirements.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
This skill should be used when the user asks about developing, building, debugging, packaging, or certifying a custom Power BI visual with the pbiviz toolchain (powerbi-visuals-tools). Covers environment setup, the visual project structure, capabilities.json (data roles, dataView mappings, objects, features, privileges), the IVisual API lifecycle (constructor, update, getFormattingModel, destroy), reading the dataView (categorical, table, matrix, single), the modern format pane and formatting model utils, selection and cross-filtering, tooltips, context menus, drill-down, bookmarks, landing pages, rendering events, local storage, launchUrl, D3 rendering, unit testing, ESLint, packaging to a .pbiviz file, and submitting to AppSource / Partner Center for certification. Example user requests: "create a custom Power BI visual", "build a bar chart visual with pbiviz", "add a format pane card to my visual", "make my visual cross-filter other visuals", "why is my visual data view empty", "get my Power BI visual cert
Advanced Microsoft Fabric GitOps and CI/CD patterns for workspace Git integration, branch governance, deployment pipelines, and release validation.
Deep expertise in Power BI development including DAX measures, Power Query M transformations, semantic model design, PBIP project scaffolding, REST API workspace management, and Microsoft Fabric integration with Lakehouse and Direct Lake.
Reusable pattern for creating an Entra app registration, generating a cert, storing the PFX in Azure Key Vault, and wiring cert-based app-only + delegated auth into a Node/TypeScript MCP. Use whenever you need Claude to talk to a Microsoft API (Graph, Power BI, Fabric, Power Platform, Dynamics) without shared secrets or device-code prompts.
Data visualization with @fluentui/react-charting — LineChart, BarChart, PieChart, DonutChart, AreaChart, HeatMapChart, SankeyChart, TreeChart, GaugeChart, theming integration, responsive patterns, and accessibility in charts.
Fluent UI for iOS (Swift/UIKit) and Android (Kotlin) — platform setup, component catalogs, design token parity, CocoaPods/SPM for iOS, Gradle for Android, and Figma design kits for each platform.
| name | Defender Endpoint |
| description | Deep expertise in Defender Endpoint operations with deterministic runbooks, fail-fast context validation, and redacted output requirements. |
| allowed-tools | ["Read","Write","Edit","Glob","Grep","Bash"] |
| triggers | ["defender endpoint","endpoint triage","isolate machine","live response","endpoint evidence"] |
docs/integration-context.md| Workflow | tenantId | subscriptionId | environmentCloud | principalType | scopesOrRoles |
|---|---|---|---|---|---|
| Defender Endpoint operations | required | optional | AzureCloud* | service-principal or delegated-user | SecurityAlert.Read.All, SecurityIncident.Read.All, ThreatHunting.Read.All, Machine.Isolate |
Fail fast before API calls when required context is missing or malformed. Redact tenant, subscription, and object identifiers.
| Command | Purpose |
|---|---|
defender-endpoint-setup | Deterministic workflow for defender endpoint setup. |
defender-endpoint-triage | Deterministic workflow for defender endpoint triage. |
defender-endpoint-isolate-machine | Deterministic workflow for defender endpoint isolate machine. |
defender-endpoint-live-response-metadata | Deterministic workflow for defender endpoint live response metadata. |
defender-endpoint-evidence-summary | Deterministic workflow for defender endpoint evidence summary. |
| Topic | File |
|---|---|
| Endpoint and permission reference | references/api-reference.md |