ms-incident-response
Installation
SKILL.md
Microsoft Incident Response
Use when
- The user reports a suspicious Microsoft alert, compromised account, mailbox abuse, endpoint compromise, or mixed identity plus endpoint activity.
- The task is to classify a potential true positive, scope impact, contain active compromise, or write an incident summary.
Required inputs
- Preferred inputs:
UPN, device/host name, alert or incident ID, and a UTC time window. - If the user principal name or host is missing, ask for it before querying Microsoft data.