← Files Aivana Security InvestigatorARCHIVED FILE
.codex-plugin/plugin.json
1.53 KB · Sep 30, 2026 · 23:15 UTC
{
"author": {
"name": "Aivana"
},
"description": "Guided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.",
"interface": {
"brandColor": "#0F766E",
"brandColorDark": "#89F0E8",
"capabilities": [
"Direct OAuth/OBO Defender XDR KQL API",
"Read-only cross-domain investigations",
"Evidence packages and analyst review"
],
"category": "Security",
"composerIcon": "./.codex-plugin/assets/composer-icon.png",
"defaultPrompt": [
"Translate this investigation question to KQL and run it safely.",
"Validate this Defender XDR KQL before running it.",
"Prepare an evidence package for analyst review."
],
"developerName": "Aivana",
"displayName": "Aivana Security Investigator",
"logo": "./.codex-plugin/assets/logo.png",
"longDescription": "Translates user requests into transparent KQL and executes bounded, read-only Defender XDR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response execution.",
"privacyPolicyURL": "https://aivana-gmbh.ai/Privacy",
"shortDescription": "Run safe KQL investigations",
"termsOfServiceURL": "https://aivana-gmbh.ai/Terms",
"websiteURL": "https://aivana-gmbh.ai/"
},
"keywords": [
"defender-xdr",
"soc",
"security-investigation",
"kql",
"microsoft-graph",
"sentinel"
],
"license": "UNLICENSED",
"name": "aivana-xdr-investigator",
"skills": "./skills",
"version": "1.1.1"
}SHA-256: fa6424fb2e871d5ad56017726b2d9dece5961e016312bb6eb9da5e3c37367838