← Plugin catalog
Security

Aivana Security Investigator

Aivana v1.1.1

Translates user requests into transparent KQL and executes bounded, read-only Defender XDR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response execution.

Language: English · Automatically detected from descriptions.

Package details

Publisher declarations from the archived package. These are separate from our research and the live service's terms.

Package license
UNLICENSED
Package author
Aivana
Keywords
defender-xdr, soc, security-investigation, kql, microsoft-graph, sentinel

Declared capabilities

  • Direct OAuth/OBO Defender XDR KQL API
  • Read-only cross-domain investigations
  • Evidence packages and analyst review

Package observed Sep 30, 2026.

Files & skills

File archives

Plugin package7 files · 3.77 MBBrowse files →
Skill instructions
analyst-review1.05 KB

View saved version →

---
name: analyst-review
description: Use when preparing or reviewing a reproducible security evidence package.
---

Purpose: hand a bounded investigation to a human analyst with facts, inferences, alternatives, and explicit response boundaries.

Prerequisites: an existing case and reproducible evidence references.

Inputs: case ID, evidence package, analyst decision, and evidence IDs.

Workflow: retrieve evidence package → assess quality and confidence → record analyst review → choose a bounded next step or closure recommendation.

Allowed tools: case evidence package, quality, confidence, review, closure-readiness, and outcome-agent brief tools.

Security constraints: no automated response, case closure, or verdict; human review remains required.

Output: review-ready package, recorded decision, evidence gaps, and next safe action.

Failure modes: missing evidence, inconsistent hypotheses, insufficient reviewer authority, or unresolved response proposal.

Tests: evidence package, review, confidence, closure-readiness, and autonomy-boundary tests.
investigation1 KB

View saved version →

---
name: investigation
description: Use when starting or governing an evidence-backed Microsoft security investigation.
---

Purpose: create a bounded case, plan safe pivots, and preserve facts, inferences, alternatives and approval boundaries.

Prerequisites: authenticated MCP caller and an explicit entity or case ID.

Inputs: entity value, objective, priority, lookback window.

Workflow: `start_security_investigation` → `run_investigation_plan` or domain hunts → evidence graph/timeline → quality, confidence and closure assessments.

Allowed tools: read-only hunting, local case/evidence/graph/report tools.

Security constraints: no external response execution; no raw-result persistence; no verdict from a single signal.

Output: case ID, reproducible evidence references, next safe action, gaps and stop condition.

Failure modes: unavailable tenant connector, insufficient scope, unknown schema, no safe template, contradictory evidence.

Tests: MCP workflow, evidence graph, confidence, closure readiness.
xdr-hunting1.05 KB

View saved version →

---
name: xdr-hunting
description: Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.
---

Purpose: translate user intent into KQL, execute it through the direct OAuth-protected API, and return bounded evidence.

Prerequisites: a concrete investigative question and OAuth authorization for the user's tenant.

Inputs: entity or validated KQL, lookback, selected fields and result cap.

Workflow: translate intent → preview/validate KQL → execute bounded read-only query → summarize result → save compact case fact.

Allowed tools: KQL translation, validation, direct API execution, entity templates and evidence tools.

Security constraints: no management commands, external data, wildcard search/union, raw result persistence or automated verdict.

Output: bounded result summary, source query, evidence reference and next review pivot.

Failure modes: quota, missing table, insufficient role, no data, unsafe query or schema mismatch.

Tests: KQL validator, direct API and result-summary tests.
Technical details
First seen
Sep 30, 2026 · 22:02 UTC
Last seen
Oct 1, 2026 · 12:00 UTC
Collection status
Collected

plugins_6a9464ad86dc8191bd1a478b38296c88

Download listing JSON