incident-investigation

Community

End-to-end security incident investigations.

AuthorSCStelz
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill automates end-to-end security incident investigations by orchestrating metadata retrieval, alert listing, asset enumeration, evidences extraction, and deep entity analysis using Defender XDR and Sentinel MCP tools.

Core Features & Use Cases

  • Incident metadata retrieval: Pulls incident details (title, severity, status, MITRE techniques) and related context.
  • Comprehensive asset & evidence gathering: Enumerates devices, users, apps, cloud resources, and evidences (malicious/suspicious processes, files, IPs, URLs, domains) with filtering and defanging.
  • Phase-driven workflow & workspace management: Enforces mandatory Sentinel workspace selection, presents entity summaries, and supports parallel investigations across users, devices, and IoCs.
  • In-depth investigations: Leverages user-investigation, computer-investigation, and ioc-investigation skills to surface findings and deliver structured outputs ready for reporting.
  • Use Case: When a security incident is identified, the skill guides operators through a reproducible, auditable investigation from incident description to actionable results.

Quick Start

Install prerequisites and start an incident investigation by supplying an incident ID, then select assets/entities for deeper analysis and generate a structured report.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: incident-investigation
Download link: https://github.com/SCStelz/security-investigator/archive/main.zip#incident-investigation

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.