ms-incident-response

Installation
SKILL.md

Microsoft Incident Response

Use when

  • The user reports a suspicious Microsoft alert, compromised account, mailbox abuse, endpoint compromise, or mixed identity plus endpoint activity.
  • The task is to classify a potential true positive, scope impact, contain active compromise, or write an incident summary.

Required inputs

  • Preferred inputs: UPN, device/host name, alert or incident ID, and a UTC time window.
  • If the user principal name or host is missing, ask for it before querying Microsoft data.
Installs
5
GitHub Stars
3
First Seen
Mar 30, 2026
ms-incident-response — crtvrffnrt/skills