← Aivana Security InvestigatorCONTENT HISTORY

Update to Aivana Security Investigator

Snapshot Oct 9, 2026 · 00:00 UTC · version 1.1.1

WHAT CHANGED · RULE-BASED ANALYSIS

Package or technical metadata updated

Discoverability changed from “UNLISTED” to “LISTED”.

Observed in package metadata. These changes alone do not establish a new customer-facing feature.

Discoverability

Before

UNLISTED

After

LISTED

Compare saved observations

Download comparison JSON
Full technical diff · 1 changed fields

changed /discoverability

BEFORE
"UNLISTED"
AFTER
"LISTED"
Full snapshot data
{
  "canonical_app_id": null,
  "connector_id": null,
  "created_at": "2026-08-30T17:15:53.125874Z",
  "discoverability": "LISTED",
  "id": "plugins_6a9464ad86dc8191bd1a478b38296c88",
  "is_template": false,
  "name": "aivana-xdr-investigator",
  "release": {
    "app_ids": [],
    "app_manifest": null,
    "app_templates": [],
    "description": "Guided, governed Microsoft security investigations for SOC analysts using a direct OAuth-protected KQL API.",
    "display_name": "Aivana Security Investigator",
    "id": "pluginrel_8e37ca1cba608191b0695351a62fb521",
    "interface": {
      "brand_color": "#0F766E",
      "capabilities": [
        "Direct OAuth/OBO Defender XDR KQL API",
        "Read-only cross-domain investigations",
        "Evidence packages and analyst review"
      ],
      "category": "Security",
      "composer_icon_dark_url": null,
      "composer_icon_url": "https://files.openai.com/content?id=file_00000000c398820c920884625adb3500",
      "default_prompt": "Translate this investigation question to KQL and run it safely.",
      "default_prompts": [
        "Translate this investigation question to KQL and run it safely.",
        "Validate this Defender XDR KQL before running it.",
        "Prepare an evidence package for analyst review."
      ],
      "developer_name": "Aivana",
      "logo_url": "https://files.openai.com/content?id=file_000000009ea481f482fc54e9f840ee55",
      "logo_url_dark": null,
      "long_description": "Translates user requests into transparent KQL and executes bounded, read-only Defender XDR queries through a direct OAuth/OBO API, then produces reproducible evidence packages and analyst review without response execution.",
      "plugin_category_id": "security",
      "privacy_policy_url": "https://aivana-gmbh.ai/Privacy",
      "screenshot_urls": [],
      "short_description": "Run safe KQL investigations",
      "terms_of_service_url": "https://aivana-gmbh.ai/Terms",
      "website_url": "https://aivana-gmbh.ai/"
    },
    "keywords": [
      "defender-xdr",
      "soc",
      "security-investigation",
      "kql",
      "microsoft-graph",
      "sentinel"
    ],
    "onboarding_skill_name": null,
    "requires_local_executor": false,
    "skills": [
      {
        "description": "Use when preparing or reviewing a reproducible security evidence package.",
        "interface": {
          "brand_color": null,
          "default_prompt": null,
          "display_name": "analyst-review",
          "icon_large_url": null,
          "icon_small_url": null,
          "iconography": "hierarchy",
          "short_description": "Use when preparing or reviewing a reproducible security evidence package."
        },
        "name": "analyst-review",
        "plugin_release_skill_id": "pluginrsk_6a94685fb4b48191b3bdb7a1a59090f2"
      },
      {
        "description": "Use when starting or governing an evidence-backed Microsoft security investigation.",
        "interface": {
          "brand_color": null,
          "default_prompt": null,
          "display_name": "investigation",
          "icon_large_url": null,
          "icon_small_url": null,
          "iconography": "hierarchy",
          "short_description": "Use when starting or governing an evidence-backed Microsoft security investigation."
        },
        "name": "investigation",
        "plugin_release_skill_id": "pluginrsk_6a94685ea58c8191a424469fe6a0c091"
      },
      {
        "description": "Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API.",
        "interface": {
          "brand_color": null,
          "default_prompt": null,
          "display_name": "xdr-hunting",
          "icon_large_url": null,
          "icon_small_url": null,
          "iconography": "radar",
          "short_description": "Use when translating user intent into bounded, validated Microsoft Defender XDR KQL and running it through the direct API."
        },
        "name": "xdr-hunting",
        "plugin_release_skill_id": "pluginrsk_6a94685f14348191b296f0624d66192d"
      }
    ],
    "version": "1.1.1"
  },
  "scope": "GLOBAL",
  "status": "ENABLED"
}

SHA-256 of public snapshot: 9eb29777614d4f1cdb2b19c2f0d4f1514cc4fb01a61fa35009c5a9c71e7f0002