unified-secops-platform
Installation
SKILL.md
Unified SecOps Platform (Microsoft Defender portal)
The unified security operations platform consolidates SIEM (Microsoft Sentinel), XDR (Microsoft Defender XDR), Microsoft Security Copilot, Microsoft Defender Threat Intelligence, and Microsoft Security Exposure Management into a single experience in the Microsoft Defender portal (security.microsoft.com).
When to use
Standardising the SOC on one portal, unifying the incident queue across SIEM and XDR signals, and reducing context-switching for analysts.
Do not use this skill for:
- Workspace, data connector, or analytics rule design only (use
sentinel) - Endpoint/identity/email/cloud-app investigation only (use
defender-xdr) - Threat-hunting query writing only (use
sentinelfor KQL guidance)