ingest-entra-directory-audit-ocsf

Installation
SKILL.md

ingest-entra-directory-audit-ocsf

Convert verified Microsoft Entra directoryAudit payloads into OCSF 1.8 API Activity records with deterministic IDs and source-preserving correlation keys.

Use when

  • You have Microsoft Graph directoryAudit exports from /auditLogs/directoryAudits and need OCSF or native output
  • You want to normalize Entra application, service-principal, and federated-credential audit activity for SIEM, lake, MCP, or downstream detection use
  • You need a portable Entra identity event stream that preserves Graph id, correlationId, activityDateTime, and target resource IDs
  • You want Graph audit events represented as OCSF API Activity before feeding them into cross-cloud identity detections

Do NOT use

  • On Azure Activity Logs, Okta System Log, Google Workspace audit logs, or CloudTrail
  • To collect live Graph data by itself — upstream collection and auth stay outside this skill
  • To infer ATT&CK techniques or create findings directly
  • To mutate Entra applications, service principals, role assignments, or federated credentials
Installs
1
GitHub Stars
3
First Seen
Apr 20, 2026
ingest-entra-directory-audit-ocsf — msaad00/cloud-ai-security-skills