Analyzing Azure Activity Logs For Threats

mukul975/analyzing-azure-activity-logs-for-threats · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 1.6 KB
  • 📁scripts
  • ⚙️agent.py 6.8 KB
  • 📄LICENSE 11.0 KB

Related

  1. Building Cloud Siem With Sentinel · mukul975 bundle
    Deploy Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations across AWS, Azure, and GCP.
    24.6k
    repo stars
  2. Azure Diagnostics · microsoft bundle
    Debug and troubleshoot Azure production issues using AppLens, Azure Monitor, resource health, and systematic diagnosis flows for services like App Service, Functions, AKS, Container Apps, and Messaging.
    2.7k
    repo stars
  3. Detecting Azure Service Principal Abuse · mukul975 bundle
    Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.
    24.6k
    repo stars
  4. Detecting AWS Cloudtrail Anomalies · mukul975 bundle
    Query AWS CloudTrail events with boto3, build statistical baselines of normal API activity, and detect anomalies such as unusual event sources, geographic anomalies, high-frequency API calls, and first-time API usage patterns.
    24.6k
    repo stars
  5. Azure Monitor Query Java · microsoft bundle
    Execute Kusto queries against Log Analytics workspaces and query metrics from Azure resources using the Azure Monitor Query SDK for Java.
    2.7k
    repo stars
  6. Detecting Azure Lateral Movement · mukul975 bundle
    Detect lateral movement in Azure AD/Entra ID environments using Microsoft Graph API audit logs, Azure Sentinel KQL hunting queries, and sign-in anomaly correlation to identify privilege escalation, token theft, and cross-tenant pivoting.
    24.6k
    repo stars

Frequently asked questions

How do I install the Analyzing Azure Activity Logs For Threats skill?

Run npx skillmds add mukul975/analyzing-azure-activity-logs-for-threats in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the Analyzing Azure Activity Logs For Threats skill do?

Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. It is listed under Security, DevOps & Infra, Cloud Platforms, Incident Response on SkillMD.

Is Analyzing Azure Activity Logs For Threats safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with Analyzing Azure Activity Logs For Threats?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is Analyzing Azure Activity Logs For Threats free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published Analyzing Azure Activity Logs For Threats?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.