incident-investigation
CommunityEnd-to-end security incident investigations.
Data & Analytics#investigate#incident-analysis#security-incident#Sentinel-MCP#Defender-XDR#workspace-selection
AuthorSCStelz
Version1.0.0
Installs0
System Documentation
What problem does it solve?
This Skill automates end-to-end security incident investigations by orchestrating metadata retrieval, alert listing, asset enumeration, evidences extraction, and deep entity analysis using Defender XDR and Sentinel MCP tools.
Core Features & Use Cases
- Incident metadata retrieval: Pulls incident details (title, severity, status, MITRE techniques) and related context.
- Comprehensive asset & evidence gathering: Enumerates devices, users, apps, cloud resources, and evidences (malicious/suspicious processes, files, IPs, URLs, domains) with filtering and defanging.
- Phase-driven workflow & workspace management: Enforces mandatory Sentinel workspace selection, presents entity summaries, and supports parallel investigations across users, devices, and IoCs.
- In-depth investigations: Leverages user-investigation, computer-investigation, and ioc-investigation skills to surface findings and deliver structured outputs ready for reporting.
- Use Case: When a security incident is identified, the skill guides operators through a reproducible, auditable investigation from incident description to actionable results.
Quick Start
Install prerequisites and start an incident investigation by supplying an incident ID, then select assets/entities for deeper analysis and generate a structured report.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: incident-investigation Download link: https://github.com/SCStelz/security-investigator/archive/main.zip#incident-investigation Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.