← Plugin catalog
Security
Aivana Security Investigator
Aivana v1.1.1
Translates user requests into transparent KQL and executes bounded, read-only Defender XDR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response execution.
Language: English · Automatically detected from descriptions.
Package details
Publisher declarations from the archived package. These are separate from our research and the live service's terms.
- Package license
- UNLICENSED
- Package author
- Aivana
- Keywords
- defender-xdr, soc, security-investigation, kql, microsoft-graph, sentinel
Declared capabilities
- Direct OAuth/OBO Defender XDR KQL API
- Read-only cross-domain investigations
- Evidence packages and analyst review
Package observed Sep 30, 2026.
Files & skills
File archives
Plugin package7 files · 3.77 MBBrowse files →
Skill instructions
analyst-review1.05 KB
--- name: analyst-review description: Use when preparing or reviewing a reproducible security evidence package. --- Purpose: hand a bounded investigation to a human analyst with facts, inferences, alternatives, and explicit response boundaries. Prerequisites: an existing case and reproducible evidence references. Inputs: case ID, evidence package, analyst decision, and evidence IDs. Workflow: retrieve evidence package → assess quality and confidence → record analyst review → choose a bounded next step or closure recommendation. Allowed tools: case evidence package, quality, confidence, review, closure-readiness, and outcome-agent brief tools. Security constraints: no automated response, case closure, or verdict; human review remains required. Output: review-ready package, recorded decision, evidence gaps, and next safe action. Failure modes: missing evidence, inconsistent hypotheses, insufficient reviewer authority, or unresolved response proposal. Tests: evidence package, review, confidence, closure-readiness, and autonomy-boundary tests.
investigation1 KB
--- name: investigation description: Use when starting or governing an evidence-backed Microsoft security investigation. --- Purpose: create a bounded case, plan safe pivots, and preserve facts, inferences, alternatives and approval boundaries. Prerequisites: authenticated MCP caller and an explicit entity or case ID. Inputs: entity value, objective, priority, lookback window. Workflow: `start_security_investigation` → `run_investigation_plan` or domain hunts → evidence graph/timeline → quality, confidence and closure assessments. Allowed tools: read-only hunting, local case/evidence/graph/report tools. Security constraints: no external response execution; no raw-result persistence; no verdict from a single signal. Output: case ID, reproducible evidence references, next safe action, gaps and stop condition. Failure modes: unavailable tenant connector, insufficient scope, unknown schema, no safe template, contradictory evidence. Tests: MCP workflow, evidence graph, confidence, closure readiness.
xdr-hunting1.05 KB
--- name: xdr-hunting description: Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API. --- Purpose: translate user intent into KQL, execute it through the direct OAuth-protected API, and return bounded evidence. Prerequisites: a concrete investigative question and OAuth authorization for the user's tenant. Inputs: entity or validated KQL, lookback, selected fields and result cap. Workflow: translate intent → preview/validate KQL → execute bounded read-only query → summarize result → save compact case fact. Allowed tools: KQL translation, validation, direct API execution, entity templates and evidence tools. Security constraints: no management commands, external data, wildcard search/union, raw result persistence or automated verdict. Output: bounded result summary, source query, evidence reference and next review pivot. Failure modes: quota, missing table, insufficient role, no data, unsafe query or schema mismatch. Tests: KQL validator, direct API and result-summary tests.
Technical details
- First seen
- Sep 30, 2026 · 22:02 UTC
- Last seen
- Oct 1, 2026 · 12:00 UTC
- Collection status
- Collected
plugins_6a9464ad86dc8191bd1a478b38296c88
Download listing JSON