← Aivana Security InvestigatorCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
changed
Update to Aivana Security Investigator
Snapshot Oct 9, 2026 · 00:00 UTC · version 1.1.1
Package or technical metadata updated
Discoverability changed from “UNLISTED” to “LISTED”.
Observed in package metadata. These changes alone do not establish a new customer-facing feature.
Discoverability
Before
UNLISTED
After
LISTED
Compare saved observations
Download comparison JSONFull technical diff · 1 changed fields
changed /discoverability
BEFORE
"UNLISTED"
AFTER
"LISTED"
Full snapshot data
{
"canonical_app_id": null,
"connector_id": null,
"created_at": "2026-08-30T17:15:53.125874Z",
"discoverability": "LISTED",
"id": "plugins_6a9464ad86dc8191bd1a478b38296c88",
"is_template": false,
"name": "aivana-xdr-investigator",
"release": {
"app_ids": [],
"app_manifest": null,
"app_templates": [],
"description": "Guided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.",
"display_name": "Aivana Security Investigator",
"id": "pluginrel_8e37ca1cba608191b0695351a62fb521",
"interface": {
"brand_color": "#0F766E",
"capabilities": [
"Direct OAuth/OBO Defender XDR KQL API",
"Read-only cross-domain investigations",
"Evidence packages and analyst review"
],
"category": "Security",
"composer_icon_dark_url": null,
"composer_icon_url": "https://files.openai.com/content?id=file_00000000c398820c920884625adb3500",
"default_prompt": "Translate this investigation question to KQL and run it safely.",
"default_prompts": [
"Translate this investigation question to KQL and run it safely.",
"Validate this Defender XDR KQL before running it.",
"Prepare an evidence package for analyst review."
],
"developer_name": "Aivana",
"logo_url": "https://files.openai.com/content?id=file_000000009ea481f482fc54e9f840ee55",
"logo_url_dark": null,
"long_description": "Translates user requests into transparent KQL and executes bounded, read-only Defender XDR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response execution.",
"plugin_category_id": "security",
"privacy_policy_url": "https://aivana-gmbh.ai/Privacy",
"screenshot_urls": [],
"short_description": "Run safe KQL investigations",
"terms_of_service_url": "https://aivana-gmbh.ai/Terms",
"website_url": "https://aivana-gmbh.ai/"
},
"keywords": [
"defender-xdr",
"soc",
"security-investigation",
"kql",
"microsoft-graph",
"sentinel"
],
"onboarding_skill_name": null,
"requires_local_executor": false,
"skills": [
{
"description": "Use when preparing or reviewing a reproducible security evidence package.",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "analyst-review",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "hierarchy",
"short_description": "Use when preparing or reviewing a reproducible security evidence package."
},
"name": "analyst-review",
"plugin_release_skill_id": "pluginrsk_6a94685fb4b48191b3bdb7a1a59090f2"
},
{
"description": "Use when starting or governing an evidence-backed Microsoft security investigation.",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "investigation",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "hierarchy",
"short_description": "Use when starting or governing an evidence-backed Microsoft security investigation."
},
"name": "investigation",
"plugin_release_skill_id": "pluginrsk_6a94685ea58c8191a424469fe6a0c091"
},
{
"description": "Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.",
"interface": {
"brand_color": null,
"default_prompt": null,
"display_name": "xdr-hunting",
"icon_large_url": null,
"icon_small_url": null,
"iconography": "radar",
"short_description": "Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API."
},
"name": "xdr-hunting",
"plugin_release_skill_id": "pluginrsk_6a94685f14348191b296f0624d66192d"
}
],
"version": "1.1.1"
},
"scope": "GLOBAL",
"status": "ENABLED"
}SHA-256 of public snapshot: 9eb29777614d4f1cdb2b19c2f0d4f1514cc4fb01a61fa35009c5a9c71e7f0002