building-cloud-siem-with-sentinel

mukul975/building-cloud-siem-with-sentinel · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Deploy Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations across AWS, Azure, and GCP.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 1.9 KB
  • 📁scripts
  • ⚙️agent.py 6.7 KB
  • 📄LICENSE 11.0 KB

Related

  1. performing-cloud-forensics-investigation · mukul975 bundle
    Collect and analyze logs, snapshots, and metadata from AWS, Azure, and GCP to investigate security breaches in cloud environments.
    24.6k
    repo stars
  2. emulating-cloud-attacks-with-stratus-red-team · mukul975 bundle
    Detonate granular AWS, Azure, GCP, and Kubernetes attack techniques to validate detections with Stratus Red Team.
    24.6k
    repo stars
  3. deploying-cloud-deception-with-decoy-resources · mukul975 bundle
    Deploy cloud-native deception across AWS, Azure, and GCP using decoy resources that generate high-fidelity alerts when attackers interact with them.
    24.6k
    repo stars
  4. conducting-cloud-incident-response · mukul975 bundle
    Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment, cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure.
    24.6k
    repo stars
  5. detecting-compromised-cloud-credentials · mukul975 bundle
    Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible travel patterns, unauthorized resource provisioning, and credential abuse indicators using GuardDuty, Defender for Identity, and SCC Event Threat Detection.
    24.6k
    repo stars
  6. analyzing-azure-activity-logs-for-threats · mukul975 bundle
    Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.
    24.6k
    repo stars

Frequently asked questions

How do I install the building-cloud-siem-with-sentinel skill?

Run npx skillmds add mukul975/building-cloud-siem-with-sentinel in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the building-cloud-siem-with-sentinel skill do?

Deploy Microsoft Sentinel as a cloud-native SIEM and SOAR platform for centralized security operations across AWS, Azure, and GCP. It is listed under Security, DevOps & Infra, Cloud Platforms, Incident Response on SkillMD.

Is building-cloud-siem-with-sentinel safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with building-cloud-siem-with-sentinel?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is building-cloud-siem-with-sentinel free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published building-cloud-siem-with-sentinel?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.