
Azure Kusto Irql
作者 microsoft354361d83247MIT收录于 2026年10月8日更新于 2026年10月8日
Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. Translates natural language hunting questions into composable IRQL pipelines using Get_*, Extract_*, and Enrich_* functions. WHEN: IRQL query, security hunt, threat hunting KQL, incident response query, compose hunting pipeline, failed logins, phishing investigation, lateral movement, process execution, file creation events.
- 354361d83247当前提交 354361d发布于 2026年10月8日
来源与署名
来源:microsoft/skills位于.github/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql提交354361d
许可证: MIT
内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。
更多来自 microsoft/skills 的技能

Customize
microsoft
以交互式引导流程部署 Azure OpenAI 模型,可自定义版本、SKU、容量和内容筛选。

Discover Azure Skills
microsoft
搜索 GitHub 上的 Azure 技能目录,并推荐与 Azure 任务匹配的可安装智能体技能。

Azure Resource Visualizer
microsoft
分析 Azure 资源组,并生成包含详细 Mermaid 架构图及资源关系说明的 Markdown 文档。

Azure Resource Lookup
microsoft
使用 Azure Resource Graph 查询和 MCP 工具,跨订阅列出和查找 Azure 资源。

Azure Messaging
microsoft
排查并解决 Azure 事件中心和 Service Bus SDK 的连接、身份验证和消息处理问题。

Azure Kusto
microsoft
在 Azure Data Explorer(Kusto)中执行 KQL 查询并浏览架构,用于日志、遥测和时间序列分析。
更多Security技能

Compliance Tracking
anthropics
跟踪合规要求、审计准备情况以及 SOC 2、ISO 27001、GDPR、HIPAA 和 PCI DSS 等框架的证据。

Dpop Adoption
指导为 Google OAuth 平台实现 OAuth 2.0 DPoP(RFC 9449)发送方约束刷新令牌。

Secops Triage
指导 SOC 分析师对 Google SecOps 安全告警进行分诊,从调查到关闭或升级。

Secops Investigate
指导 SOC 分析师在 Google SecOps 中使用 UDM 查询和时间线进行深入的安全事件与实体调查。

Secops Hunt
指导在 Google SecOps 中使用 UDM 查询、IoC 回溯、普遍性与异常分析进行主动威胁狩猎。

Secops Cases
通过 MCP 工具管理 Google Security Operations SOAR 案例的整个生命周期。