
Azure Kusto Irql
作者 microsoft354361d83247MIT收錄於 2026年10月8日更新於 2026年10月8日
Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. Translates natural language hunting questions into composable IRQL pipelines using Get_*, Extract_*, and Enrich_* functions. WHEN: IRQL query, security hunt, threat hunting KQL, incident response query, compose hunting pipeline, failed logins, phishing investigation, lateral movement, process execution, file creation events.
僅公開檔案列表。將技能安裝到工作區後即可檢視檔案內容。
| 路徑 | 大小 | 類型 |
|---|---|---|
| references/EXAMPLES.md | 2.2 KB | text/markdown |
| references/KUSTO_EXPLORER_LAUNCH.md | 2.6 KB | text/markdown |
| SKILL.md | 10.2 KB | text/markdown |
來源與署名
來源:microsoft/skills位於.github/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql提交354361d
授權條款: MIT
內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。
更多來自 microsoft/skills 的技能

Customize
microsoft
以互動式引導流程部署 Azure OpenAI 模型,可自訂版本、SKU、容量與內容篩選。

Discover Azure Skills
microsoft
搜尋 GitHub 上的 Azure 技能目錄,並推薦符合 Azure 工作的可安裝代理技能。

Azure Resource Visualizer
microsoft
分析 Azure 資源群組,並產出內含詳細 Mermaid 架構圖與資源關係說明的 Markdown 文件。

Azure Resource Lookup
microsoft
使用 Azure Resource Graph 查詢與 MCP 工具,跨訂閱列出和尋找 Azure 資源。

Azure Messaging
microsoft
疑難排解並解決 Azure 事件中樞與 Service Bus SDK 的連線、驗證和訊息處理問題。

Azure Kusto
microsoft
在 Azure Data Explorer(Kusto)中執行 KQL 查詢並探索結構描述,用於日誌、遙測與時間序列分析。
更多Security技能

Compliance Tracking
anthropics
追蹤合規要求、稽核準備情況,以及 SOC 2、ISO 27001、GDPR、HIPAA 和 PCI DSS 等框架的證據。

Dpop Adoption
指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Secops Triage
引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Secops Investigate
指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Secops Hunt
指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。

Secops Cases
透過 MCP 工具管理 Google Security Operations SOAR 案件的完整生命週期。