← Aivana Security InvestigatorCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Aivana Security Investigator
Snapshot Sep 30, 2026 · 23:15 UTC · version 1.1.1
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "xdr-hunting",
"description": "Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.",
"included_files": [],
"skill_md_contents": "---\nname: xdr-hunting\ndescription: Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.\n---\n\nPurpose: translate user intent into KQL, execute it through the direct OAuth-protected API, and return bounded evidence.\n\nPrerequisites: a concrete investigative question and OAuth authorization for the user's tenant.\n\nInputs: entity or validated KQL, lookback, selected fields and result cap.\n\nWorkflow: translate intent → preview/validate KQL → execute bounded read-only query → summarize result → save compact case fact.\n\nAllowed tools: KQL translation, validation, direct API execution, entity templates and evidence tools.\n\nSecurity constraints: no management commands, external data, wildcard search/union, raw result persistence or automated verdict.\n\nOutput: bounded result summary, source query, evidence reference and next review pivot.\n\nFailure modes: quota, missing table, insufficient role, no data, unsafe query or schema mismatch.\n\nTests: KQL validator, direct API and result-summary tests.\n"
}SHA-256: e23807d37f0eeab28b25ff486f88fc36c3cee7899dbbb7bb7a0eb6376fdab107