{"id":4552,"external_id":"plugins_6a9464ad86dc8191bd1a478b38296c88","name":"aivana-xdr-investigator","display_name":"Aivana Security Investigator","developer":"Aivana","category":"Security","listing_language":"en","listing_language_details":{"method":"cld-0.13.0/listing-v1","reliable":true,"detected_at":"2026-10-01T13:22:04Z","input_sha256":"67f9079f3215af9038d4ac0e2f70453553256a737d5883d65141b1901f38c1a5","source_fields":["release.description","release.interface.short_description","release.interface.long_description"]},"version":"1.1.1","skill_count":3,"first_seen_at":"2026-09-30T22:02:35.000Z","last_seen_at":"2026-10-01T12:00:01.032Z","last_changed_at":"2026-09-30T22:02:35.000Z","install_count":null,"research_summary":null,"research_reviewed_at":null,"metadata":{"id":"plugins_6a9464ad86dc8191bd1a478b38296c88","name":"aivana-xdr-investigator","scope":"GLOBAL","status":"ENABLED","release":{"id":"pluginrel_8e37ca1cba608191b0695351a62fb521","skills":[{"name":"analyst-review","interface":{"brand_color":null,"iconography":"hierarchy","display_name":"analyst-review","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Use when preparing or reviewing a reproducible security evidence package."},"description":"Use when preparing or reviewing a reproducible security evidence package.","plugin_release_skill_id":"pluginrsk_6a94685fb4b48191b3bdb7a1a59090f2"},{"name":"investigation","interface":{"brand_color":null,"iconography":"hierarchy","display_name":"investigation","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Use when starting or governing an evidence-backed Microsoft security investigation."},"description":"Use when starting or governing an evidence-backed Microsoft security investigation.","plugin_release_skill_id":"pluginrsk_6a94685ea58c8191a424469fe6a0c091"},{"name":"xdr-hunting","interface":{"brand_color":null,"iconography":"radar","display_name":"xdr-hunting","default_prompt":null,"icon_large_url":null,"icon_small_url":null,"short_description":"Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API."},"description":"Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.","plugin_release_skill_id":"pluginrsk_6a94685f14348191b296f0624d66192d"}],"app_ids":[],"version":"1.1.1","keywords":["defender-xdr","soc","security-investigation","kql","microsoft-graph","sentinel"],"interface":{"category":"Security","logo_url":"https://files.openai.com/content?id=file_000000009ea481f482fc54e9f840ee55","brand_color":"#0F766E","website_url":"https://aivana-gmbh.ai/","capabilities":["Direct OAuth/OBO Defender XDR KQL API","Read-only cross-domain investigations","Evidence packages and analyst review"],"logo_url_dark":null,"default_prompt":"Translate this investigation question to KQL and run it safely.","developer_name":"Aivana","default_prompts":["Translate this investigation question to KQL and run it safely.","Validate this Defender XDR KQL before running it.","Prepare an evidence package for analyst review."],"screenshot_urls":[],"long_description":"Translates user requests into transparent KQL and executes bounded, read-only Defender XDR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response execution.","composer_icon_url":"https://files.openai.com/content?id=file_00000000c398820c920884625adb3500","short_description":"Run safe KQL investigations","plugin_category_id":"security","privacy_policy_url":"https://aivana-gmbh.ai/Privacy","terms_of_service_url":"https://aivana-gmbh.ai/Terms","composer_icon_dark_url":null},"description":"Guided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.","app_manifest":null,"display_name":"Aivana Security Investigator","app_templates":[],"onboarding_skill_name":null,"requires_local_executor":false},"created_at":"2026-08-30T17:15:53.125874Z","is_template":false,"connector_id":null,"discoverability":"UNLISTED","canonical_app_id":null},"research":null,"package_metadata":{"name":"aivana-xdr-investigator","author":{"name":"Aivana"},"license":"UNLICENSED","sources":[{"path":".codex-plugin/plugin.json","sha256":"fa6424fb2e871d5ad56017726b2d9dece5961e016312bb6eb9da5e3c37367838"}],"version":"1.1.1","keywords":["defender-xdr","soc","security-investigation","kql","microsoft-graph","sentinel"],"artifact_id":5451,"observed_at":"2026-09-30T23:15:21Z","capabilities":["Direct OAuth/OBO Defender XDR KQL API","Read-only cross-domain investigations","Evidence packages and analyst review"],"field_sources":{"name":0,"author":0,"license":0,"version":0,"keywords":0,"capabilities":0},"extraction_version":1,"conflicts_or_errors":[]}}