ingest-entra-directory-audit-ocsf
Installation
SKILL.md
ingest-entra-directory-audit-ocsf
Convert verified Microsoft Entra directoryAudit payloads into OCSF 1.8 API
Activity records with deterministic IDs and source-preserving correlation keys.
Use when
- You have Microsoft Graph
directoryAuditexports from/auditLogs/directoryAuditsand need OCSF or native output - You want to normalize Entra application, service-principal, and federated-credential audit activity for SIEM, lake, MCP, or downstream detection use
- You need a portable Entra identity event stream that preserves Graph
id,correlationId,activityDateTime, and target resource IDs - You want Graph audit events represented as OCSF API Activity before feeding them into cross-cloud identity detections
Do NOT use
- On Azure Activity Logs, Okta System Log, Google Workspace audit logs, or CloudTrail
- To collect live Graph data by itself — upstream collection and auth stay outside this skill
- To infer ATT&CK techniques or create findings directly
- To mutate Entra applications, service principals, role assignments, or federated credentials