← all publishers

dstreefkerk

@dstreefkerk source repo

11 published skills

  1. Reflect · dstreefkerk
    Review the current chat session to identify mistakes, friction, and unclear outputs. Propose improvements and check any skills used for optimization opportunities. Use when correcting course or at session end.
    0 installs
  2. Kql Expert · dstreefkerk bundle
    KQL expert for Microsoft Sentinel, Azure Monitor, and M365 Defender. Use proactively when the user works with any .kql file, writes or reviews KQL queries, develops analytics or detection rules, performs threat hunting, needs DCR transformation KQL, or asks to optimise, validate, or convert a KQL query. Covers query optimisation, schema validation, ASIM normalisation, SPL migration, and best practices.
    0 installs
  3. Powershell · dstreefkerk bundle
    Enterprise PowerShell coding standards. Use when writing, reviewing, or generating any PowerShell code, creating PS1 scripts or functions, debugging PowerShell, or asked to help with PowerShell. Enforces best practices for structure, error handling, security, performance, and output patterns.
    0 installs
  4. Slide Notes · dstreefkerk bundle
    Generate structured PowerPoint speaker notes for technical presentations. Produces runbook-style bullet notes (not scripts) that add depth beyond the slide content, including anticipated Q&A, references, emphasis cues, transitions, and time markers. Use when the user asks to write, generate, create, or improve speaker notes, presentation notes, slide notes, or PowerPoint notes. Also triggers when users provide slide content and ask for notes to accompany it. Optimised for cyber security and technical audiences but applicable to any domain.
    0 installs
  5. Cyber Impact Statement · dstreefkerk
    Generates concise, CISO-level impact statements for security control failures. Use when the user asks for an impact statement, wants to explain the business consequences of a security control failure, needs to document risk for a risk register or audit finding, or wants to translate a technical vulnerability into executive language for a CISO or board.
    0 installs
  6. Codeless Connectors · dstreefkerk bundle
    Use before writing any Microsoft Sentinel connector ARM template, DCR, KQL transform, or createUiDefinition.json. Provides the complete CCF (Codeless Connector Framework) reference for RestApiPoller, Push, and GCP connector types — including escaping rules, authentication, pagination, UI definitions, and deployment gotchas. Also use when debugging connector deployment failures or reviewing existing CCP templates.
    0 installs
  7. Stream Transcript · dstreefkerk bundle
    Extract plaintext WebVTT transcripts and detect slide transitions from Microsoft Stream (on SharePoint) video recordings. Use when the user wants to download, extract, or retrieve a transcript/captions from a Microsoft Stream video, Teams meeting recording, or SharePoint-hosted video. Also supports detecting slide changes and capturing screenshots. Triggers: "get the transcript", "download transcript", "extract captions", "stream transcript", "meeting recording transcript", "detect slides", "capture slides", "slide transitions". Requires the Playwright MCP server for browser authentication.
    0 installs
  8. Sentinel Arm Generator · dstreefkerk bundle
    Generates deployment-ready Microsoft Sentinel Analytic Rule ARM templates from KQL detection queries. Use when the user asks to create, export, or package a Sentinel analytics rule, convert a KQL query into an ARM template, or generate rule deployment files with MITRE ATT&CK mappings and entity extraction.
    0 installs
  9. Threat Modeling · dstreefkerk bundle
    Threat Modelling
    0 installs
  10. Sentinel Use Case Documentor · dstreefkerk bundle
    Documents Microsoft Sentinel analytics rules as comprehensive SOC use cases. Use when the user wants to document a Sentinel rule, create SOC documentation, generate use case docs from an ARM template, or document a KQL detection query.
    0 installs
  11. Threat Modeling Artefacts · dstreefkerk bundle
    Produce threat-modelling deliverables and artefacts — threat model documents, risk registers, kickoff packs, security acceptance criteria, executive summaries, compliance evidence packages, and squad self-serve kickstarts. Use this skill whenever the user asks to *produce*, *draft*, *generate*, *write*, or *create* a threat-modelling artefact — phrases like "draft a threat model document", "generate a risk register", "produce security acceptance criteria", "build a kickoff pack", "create an executive summary of threat model findings", "give me a TM doc for [system]", "help my squad self-serve a threat model on our component". This skill auto-detects available rendering capabilities (docx, pdf, xlsx agent skills, or Python with pandoc/openpyxl) and produces the highest-fidelity output available, falling back to markdown and CSV which work everywhere. Does *not* trigger for analytical asks like "what is STRIDE" or "what threats apply to [system]" — those go to the `threat-modeling` skill.
    0 installs