← Aivana Security InvestigatorCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Aivana Security Investigator
Snapshot Sep 30, 2026 · 23:15 UTC · version 1.1.1
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "investigation",
"description": "Use when starting or governing an evidence-backed Microsoft security investigation.",
"included_files": [],
"skill_md_contents": "---\nname: investigation\ndescription: Use when starting or governing an evidence-backed Microsoft security investigation.\n---\n\nPurpose: create a bounded case, plan safe pivots, and preserve facts, inferences, alternatives and approval boundaries.\n\nPrerequisites: authenticated MCP caller and an explicit entity or case ID.\n\nInputs: entity value, objective, priority, lookback window.\n\nWorkflow: `start_security_investigation` → `run_investigation_plan` or domain hunts → evidence graph/timeline → quality, confidence and closure assessments.\n\nAllowed tools: read-only hunting, local case/evidence/graph/report tools.\n\nSecurity constraints: no external response execution; no raw-result persistence; no verdict from a single signal.\n\nOutput: case ID, reproducible evidence references, next safe action, gaps and stop condition.\n\nFailure modes: unavailable tenant connector, insufficient scope, unknown schema, no safe template, contradictory evidence.\n\nTests: MCP workflow, evidence graph, confidence, closure readiness.\n"
}SHA-256: e885e520045e49ddbbcf63ec4e51b93a3215f28b199e63d5a5089f604af875f5