incident-investigation
Installation
SKILL.md
Incident Investigation - Instructions
Purpose
This skill performs comprehensive security investigations on incidents from Microsoft Defender XDR and Microsoft Sentinel. It retrieves incident details, lists alerts, enumerates assets and evidences, and then performs deep investigation on user-selected entities using appropriate tools and specialized skills.
Investigation Flow:
- Phase 1: Incident Description - Retrieve metadata, alerts, assets, and evidences
- Phase 2: Incident Investigation Menu - Ask the user to select the incident assets and entities that should be investigated.
- Phase 2-A: User Investigation - Follow user-investigation skill workflow
- Phase 2-B: Device Investigation - Follow computer-investigation skill workflow
- Phase 2-C: IoC Investigation - Follow ioc-investigation skill workflow for IPs, URLs, Files, Domains, Hashes
- Phase 3: Looping to Phase 2 - Ask the user to select the further assets and entities that should be investigated.