Skip to main content
SCStelz
GitHub 创作者资料

SCStelz

按仓库查看 1 个 GitHub 仓库中的 28 个已收集 skills。

已收集 skills
28
仓库
1
更新
2026年8月28日
仓库分布

Skills 分布在哪些仓库

按已收集 skill 数展示主要仓库,并显示它们在该创作者目录中的占比和职业覆盖。

仓库浏览

仓库与代表性 skills

context-memory-review
未分类

Weekly review of an investigation tenant-context memory file against the most recent SOC scan reports (e.g. Threat Pulse) and the Mission Control findings log. Surfaces candidate ADD / MODIFY / FLAG changes to the context file as a propose-only review…

2026年8月28日
ai-agent-posture
未分类

Audit or report on AI agent security posture across Copilot Studio, Microsoft 365 Copilot, Microsoft Foundry, and third-party agents. Triggers on "AI agent posture", "agent security audit", "Copilot Studio agents", "agent inventory", "broadly accessible…

2026年8月26日
sentinel-ingestion-report
未分类

Sentinel Ingestion Report — YAML-driven PowerShell pipeline gathers all data via az monitor/az rest/Graph API, writes a deterministic scratchpad, LLM renders the report. Covers table-level volume breakdown, tier classification (Analytics/Basic/Data Lake),…

2026年8月26日
ai-agent-activity
未分类

Report/investigate RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / M365 Copilot / Work IQ) — agents used, tools/connectors, channels, tokens, prompt/reply content, and Prompt Shield jailbreak/XPIA verdicts. Triggers: "agent activity", "AI agent…

2026年8月26日
detection-authoring
信息安全分析师

Create, deploy, update, and manage custom detection rules in Microsoft Defender XDR via the Graph API (/beta/security/rules/detectionRules). Covers query adaptation from Sentinel KQL to custom detection format, deployment via PowerShell…

2026年7月16日
mitre-coverage-report
信息安全分析师

MITRE ATT&CK Coverage Report — YAML-driven PowerShell pipeline gathers analytic rule MITRE tags, custom detection techniques, SOC Optimization recommendations, and alert/incident operational data via az rest/az monitor/Graph API, writes a deterministic…

2026年7月1日
threat-intel-campaign
信息安全分析师

Turn a published threat-intelligence article into a tested threat-hunting campaign. Reads a platform-agnostic RSS/Atom feed (feed_url is a parameter — nothing vendor-specific is hardcoded), triages articles from a recent window, applies a huntability…

2026年6月11日
threat-pulse
信息安全分析师

Recommended starting point for new users and daily SOC operations. 15-minute broad security scan across 7 domains (incidents, identity, NHI, endpoint, email, admin/cloud, exposure) producing a Threat Pulse Dashboard with drill-down recommendations to…

2026年5月29日
已展示 8 / 28 个已收集 Skill。
已展示 1 / 1 个仓库
已展示全部仓库