tenzir-asim

Installation
SKILL.md

Microsoft Sentinel ASIM

Microsoft Sentinel ASIM (Advanced Security Information Model) normalizes security telemetry from many products into source-independent records that analysts can query consistently. Use this skill to choose the right ASIM schema, inspect normalized fields, resolve aliases, explain field classes and logical types, and map events or entities into ASIM.

The generated YAML files are the authoritative reference for this skill. If a field, alias, enum value, schema version, condition, or schema behavior is not present in the YAML data, say that it is not documented here. Use source.md only as the final provenance anchor for the requested Microsoft Defender Docs ref and raw Markdown copies.

How ASIM fits together

ASIM is organized around schemas. A schema is a named contract for one kind of activity or entity, with a version, status, and field set. Event schemas describe activity records such as DNS, authentication, network, process, registry, file, audit, alert, web, DHCP, agent, and user-management events. Entity schemas describe standalone entity records, such as AssetEntity. A normalized event record identifies its contract with EventSchema and EventSchemaVersion; an entity record uses EntitySchema and EntitySchemaVersion.

Installs
27
Repository
tenzir/skills
GitHub Stars
3
First Seen
Jun 7, 2026
tenzir-asim — tenzir/skills