{"id":19201,"plugin_id":"plugins_6a9464ad86dc8191bd1a478b38296c88","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:22.721Z","digest":"e23807d37f0eeab28b25ff486f88fc36c3cee7899dbbb7bb7a0eb6376fdab107","against":null,"payload":{"name":"xdr-hunting","description":"Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.","included_files":[],"skill_md_contents":"---\nname: xdr-hunting\ndescription: Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.\n---\n\nPurpose: translate user intent into KQL, execute it through the direct OAuth-protected API, and return bounded evidence.\n\nPrerequisites: a concrete investigative question and OAuth authorization for the user's tenant.\n\nInputs: entity or validated KQL, lookback, selected fields and result cap.\n\nWorkflow: translate intent → preview/validate KQL → execute bounded read-only query → summarize result → save compact case fact.\n\nAllowed tools: KQL translation, validation, direct API execution, entity templates and evidence tools.\n\nSecurity constraints: no management commands, external data, wildcard search/union, raw result persistence or automated verdict.\n\nOutput: bounded result summary, source query, evidence reference and next review pivot.\n\nFailure modes: quota, missing table, insufficient role, no data, unsafe query or schema mismatch.\n\nTests: KQL validator, direct API and result-summary tests.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}