Skip to main content
在 Manus 中运行任何 Skill
一键导入
stefanpems
GitHub 创作者资料

stefanpems

按仓库查看 1 个 GitHub 仓库中的 13 个已收集 skills。

已收集 skills
13
仓库
1
更新
2026-06-04
仓库分布

Skills 分布在哪些仓库

按已收集 skill 数展示主要仓库,并显示它们在该创作者目录中的占比和职业覆盖。

仓库浏览

仓库与代表性 skills

incident-comment
信息安全分析师

Use this skill when asked to write, post, or add a comment to a Microsoft Sentinel incident. Accepts plain text, Markdown, or HTML content as input. Plain text is posted as-is; Markdown is converted to HTML optimized for the narrow Activities panel; HTML is adapted for single-column display. ALL input content is preserved in full — no summarization or truncation — unless the user explicitly requests it. Triggers on: "write comment", "add comment", "post comment", "scrivi commento", "aggiungi commento", "commenta incidente", "comment on incident", "post to incident", "annotate incident".

2026-06-04
computer-investigation
信息安全分析师

Computer/device security investigation skill for environments with Azure Monitor MCP (Log Analytics workspace queries) and Azure CLI access — currently without Sentinel Data Lake MCP, Sentinel Triage MCP, or Microsoft Graph MCP (these cannot be connected to Azure SRE Agent yet; direct API access to Sentinel Data Lake and Microsoft Graph not yet implemented). Device data from Entra ID is collected via Azure CLI (`az rest` for Graph API) or KQL fallback queries from DeviceInfo/SigninLogs. KQL queries run against Log Analytics tables through the Azure Monitor MCP tool. TVM tables (software inventory, vulnerabilities) are NOT available through Log Analytics.

2026-06-03
identity-posture
信息安全分析师

Audit identity security posture across the organization. Triggers on keywords like "identity posture", "identity security report", "account hygiene", "stale accounts", "privileged accounts", "password posture", "identity providers", "identity sprawl", "service accounts", "deleted accounts with roles", "honeytoken", "sensitive accounts", "MFA coverage", "risky users". Collects data from Microsoft Graph API (user inventory, roles, PIM, risk, MFA) and Log Analytics KQL (IdentityInfo UAC flags, MDI tags, IdentityLogonEvents, SigninLogs). Produces a posture assessment covering account inventory, privileged account audit, stale/deleted account hygiene, password posture, MFA coverage, risk distribution, MDI tag analysis, and department-level insights. Inline chat or markdown output.

2026-06-03
incident-investigation
信息安全分析师

Use this skill when asked to investigate a security incident by ID from Microsoft Defender XDR or Microsoft Sentinel. Triggers on keywords like "investigate incident", "incident ID", "incident investigation", "analyze incident", "triage incident", or when an incident number/ID is mentioned with investigation context. This skill provides comprehensive incident analysis including metadata retrieval, alert listing, asset enumeration, evidence filtering, and deep entity investigation using KQL queries via Azure Monitor MCP and specialized sub-skills. Environment: Azure Monitor MCP + Azure CLI — currently without Sentinel Data Lake MCP, Sentinel Triage MCP, or Microsoft Graph MCP (not yet connectable to Azure SRE Agent).

2026-06-03
incident-listing
信息安全分析师

Use this skill when the user asks to list, show, or enumerate recent security incidents. Ensures the KQL query against SecurityIncident is aligned with the Microsoft Defender XDR portal view (correct time filter, incident IDs, and phantom incident exclusion).

2026-06-03
incident-statistics
信息安全分析师

Use this skill when the user asks for incident statistics, incident metrics, incident reports, SOC dashboard data, MTTA/MTTR analysis, incident distribution, or any quantitative analysis of security incidents over a given time period. ALSO use this skill when the user asks for a high-level view, overview, summary, or status of SOC operations, CIRT/CSIRT activities, security operations, or the security posture in general. These requests are equivalent to asking for incident statistics because security incidents are the primary measurable output of SOC/CIRT/CSIRT work. Triggers on keywords like: "incident statistics", "incident report", "incident metrics", "how many incidents", "MTTA", "MTTR", "incident trend", "SOC metrics", "incident summary", "incident dashboard", "affected users", "affected devices", "incident assignees", "MITRE coverage", "true positive incidents", "SOC overview", "SOC status", "SOC activity", "CIRT overview", "CSIRT overview", "CIRT status", "CSIRT status", "security overview", "security

2026-06-03
ioc-investigation
信息安全分析师

IoC (Indicator of Compromise) investigation skill for environments with Azure Monitor MCP (Log Analytics workspace queries) and Azure CLI access — currently without Sentinel Data Lake MCP, Sentinel Triage MCP, or Microsoft Graph MCP (not yet connectable to Azure SRE Agent; direct API access to Sentinel Data Lake and Microsoft Graph not yet implemented). KQL queries run against Log Analytics tables through the Azure Monitor MCP tool. MDE API calls (custom IOC list, TVM) are executed via RunAzCliReadCommands (az rest). 3rd-party IP enrichment is provided by enrich_ips.py (ipinfo.io, vpnapi.io, AbuseIPDB, Shodan).

2026-06-03
mcp-usage-monitoring
信息安全分析师

Use this skill when asked to monitor, audit, or analyze MCP (Model Context Protocol) server usage in the environment. Triggers on keywords like "MCP usage", "MCP server monitoring", "MCP activity", "Graph MCP", "Sentinel MCP", "Azure MCP", "MCP audit", "tool usage monitoring", "MCP breakdown", "who is using MCP", or when investigating MCP user activity, Graph API calls from MCP servers, or workspace query governance. This skill provides comprehensive MCP server telemetry analysis across Graph MCP, Sentinel MCP, and Azure MCP servers including usage trends, endpoint access patterns, user attribution, cross-server user analysis, sensitive API detection, workspace query governance, and security risk assessment with inline and markdown file reporting.

2026-06-03
当前展示该仓库 Top 8 / 13 个已收集 skills。
已展示 1 / 1 个仓库
已展示全部仓库