← Plugin catalog
Security

Aivana Security Investigator

Aivana v1.1.1

Publisher description

From the marketplace listing

Translates user requests into transparent KQL and executes bounded, read-only Defender XDR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response execution.

Language: English · Automatically detected from descriptions.

Publisher keywords

Search terms declared by the publisher.

Matches for “guide”

Exact text from the indicated source. A mention alone does not establish support for your task.

Publisher description

Guided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.

Files & skills

File archives

Plugin package7 files · 3.77 MBBrowse files →
Skill instructions
analyst-review1.05 KB

View saved version →

---
name: analyst-review
description: Use when preparing or reviewing a reproducible security evidence package.
---

Purpose: hand a bounded investigation to a human analyst with facts, inferences, alternatives, and explicit response boundaries.

Prerequisites: an existing case and reproducible evidence references.

Inputs: case ID, evidence package, analyst decision, and evidence IDs.

Workflow: retrieve evidence package → assess quality and confidence → record analyst review → choose a bounded next step or closure recommendation.

Allowed tools: case evidence package, quality, confidence, review, closure-readiness, and outcome-agent brief tools.

Security constraints: no automated response, case closure, or verdict; human review remains required.

Output: review-ready package, recorded decision, evidence gaps, and next safe action.

Failure modes: missing evidence, inconsistent hypotheses, insufficient reviewer authority, or unresolved response proposal.

Tests: evidence package, review, confidence, closure-readiness, and autonomy-boundary tests.
investigation1 KB

View saved version →

---
name: investigation
description: Use when starting or governing an evidence-backed Microsoft security investigation.
---

Purpose: create a bounded case, plan safe pivots, and preserve facts, inferences, alternatives and approval boundaries.

Prerequisites: authenticated MCP caller and an explicit entity or case ID.

Inputs: entity value, objective, priority, lookback window.

Workflow: `start_security_investigation` → `run_investigation_plan` or domain hunts → evidence graph/timeline → quality, confidence and closure assessments.

Allowed tools: read-only hunting, local case/evidence/graph/report tools.

Security constraints: no external response execution; no raw-result persistence; no verdict from a single signal.

Output: case ID, reproducible evidence references, next safe action, gaps and stop condition.

Failure modes: unavailable tenant connector, insufficient scope, unknown schema, no safe template, contradictory evidence.

Tests: MCP workflow, evidence graph, confidence, closure readiness.
xdr-hunting1.05 KB

View saved version →

---
name: xdr-hunting
description: Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.
---

Purpose: translate user intent into KQL, execute it through the direct OAuth-protected API, and return bounded evidence.

Prerequisites: a concrete investigative question and OAuth authorization for the user's tenant.

Inputs: entity or validated KQL, lookback, selected fields and result cap.

Workflow: translate intent → preview/validate KQL → execute bounded read-only query → summarize result → save compact case fact.

Allowed tools: KQL translation, validation, direct API execution, entity templates and evidence tools.

Security constraints: no management commands, external data, wildcard search/union, raw result persistence or automated verdict.

Output: bounded result summary, source query, evidence reference and next review pivot.

Failure modes: quota, missing table, insufficient role, no data, unsafe query or schema mismatch.

Tests: KQL validator, direct API and result-summary tests.
Package details

Publisher declarations from the archived package. These are separate from our research and the live service's terms.

Package license
UNLICENSED
Package author
Aivana
Keywords
See publisher keywords

Declared capabilities

  • Direct OAuth/OBO Defender XDR KQL API
  • Read-only cross-domain investigations
  • Evidence packages and analyst review

Package observed Oct 5, 2026.

Technical details
First seen
Sep 30, 2026 · 22:02 UTC
Last seen
Oct 6, 2026 · 12:00 UTC
Collection status
Collected

plugins_6a9464ad86dc8191bd1a478b38296c88

Download plugin data (JSON)

Before you connect Aivana Security Investigator

How do I connect it?

Open the publisher's marketplace listing to check current availability and follow its connection instructions. This directory does not install plugins. Check the requested access and any account requirements before connecting.

Check marketplace availability ↗

Does it require paid access?

We have not established the pricing or subscription requirements for this plugin. An absent price does not mean free access.

Compare researched pricing and access models →

How can I evaluate it?

Check the declared skills and available files, then try a small task whose result you can verify. Our archived descriptions and instructions establish publisher claims, not tested runtime quality. Review sources and coverage limits.