← Aivana Security InvestigatorCONTENT HISTORY

Update to Aivana Security Investigator

Snapshot Sep 30, 2026 · 23:15 UTC · version 1.1.1

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "xdr-hunting",
  "description": "Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.",
  "included_files": [],
  "skill_md_contents": "---\nname: xdr-hunting\ndescription: Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.\n---\n\nPurpose: translate user intent into KQL, execute it through the direct OAuth-protected API, and return bounded evidence.\n\nPrerequisites: a concrete investigative question and OAuth authorization for the user's tenant.\n\nInputs: entity or validated KQL, lookback, selected fields and result cap.\n\nWorkflow: translate intent → preview/validate KQL → execute bounded read-only query → summarize result → save compact case fact.\n\nAllowed tools: KQL translation, validation, direct API execution, entity templates and evidence tools.\n\nSecurity constraints: no management commands, external data, wildcard search/union, raw result persistence or automated verdict.\n\nOutput: bounded result summary, source query, evidence reference and next review pivot.\n\nFailure modes: quota, missing table, insufficient role, no data, unsafe query or schema mismatch.\n\nTests: KQL validator, direct API and result-summary tests.\n"
}

SHA-256: e23807d37f0eeab28b25ff486f88fc36c3cee7899dbbb7bb7a0eb6376fdab107