scope-drift-detection
CommunityDetect scope drift across identities.
Data & Analytics#baseline#service principals#scope drift#user accounts#drift score#AuditLogs#SecurityAlert
AuthorSCStelz
Version1.0.0
Installs0
System Documentation
What problem does it solve?
Detects and quantifies scope drift across Entra ID service principals and user accounts, enabling proactive risk management by identifying gradual access expansion and behavioral changes before incidents occur.
Core Features & Use Cases
- 90-day behavioral baseline per entity (SPNs and users) with comparative drift scoring
- Cross-source correlation with AuditLogs, DeviceNetworkEvents, SecurityAlert, and Identity Protection
- Outputs inline summaries or Markdown reports for investigation handoffs
Quick Start
Ask me to run a scope drift investigation for a service principal or a user account. The skill will automatically detect the entity type, select the appropriate data sources, compute drift scores across defined dimensions, and render results in your preferred output mode.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: scope-drift-detection Download link: https://github.com/SCStelz/security-investigator/archive/main.zip#scope-drift-detection Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.