All skills
microsoft avatar

/azure-kusto-irql-graph

@4d0badd
by microsoftmicrosoft/skills3.1k stars
351

Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization. Generates Lift_To_Graph mappings and composes Graph_Render_View, Graph_Fold_By_Property, Extract_Node_*, Enrich_Node_*, and Enrich_Graph_* calls. Accepts a supplied query or limited basic natural-language source request; it is not a general natural-language-to-KQL/IRQL skill. WHEN: Lift_To_Graph, Graph_Render_View, Graph_Fold_By_Property, IRQL graph enrichment, graph mapping for existing query results, icon-decorated graph, fold graph nodes. Use azure-kusto-graph for native make-graph analysis, graph-match, shortest paths, components, or persistent graphs.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-kusto-irql-graph

This session only. Nothing lands on disk.

referencesEXAMPLES.md

≈911 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Try It Out -- azure-kusto-irql-graph

Paste any of these into Copilot Chat to see the skill in action. Cluster: https://kc7001.eastus.kusto.windows.net

Supply the source KQL/IRQL pipeline with the graph description. The skill maps the query's output columns; it does not normally author the underlying investigation query.

Use this skill for Lift_To_Graph, rendering, folding, and IRQL graph extraction/enrichment functions. Use azure-kusto-graph for native make-graph, graph-match, paths, components, graph models, and snapshots.

Before trying the prompts on another database, verify Lift_To_Graph and Graph_Render_View with .show functions; also verify Graph_Fold_By_Property or enrichers when a prompt uses them. Deploy missing definitions from references/DEPLOY_IRQL_FUNCTIONS.md.


ValdyTimes (IRQL selectors -> Lift_To_Graph)

# Ask This What It Does
1 "Given `Get_Event_Authentication_All take 200`, create a graph showing users authenticating to hosts"
2 "Given `Get_Event_Authentication_All where Result == 'Failed Login'
3 "Given `Get_Email_All take 300`, visualize email flow between senders and recipients"
4 "Given `Get_Email_All take 400`, graph emails and collapse messages by verdict"
5 "Given `Get_Event_Process_All where ProcessCommandLine has 'powershell'
6 "Given my query returning ClientIp, DomainName, and EnvTime, graph outbound connections and label IPs with employee names" Network mapping -> Enrich_Node_Ip_Employee -> render
7 "Create a graph mapping for file creation events showing which user created which file on which host" Open-ended -- Copilot generates a new mapping JSON
8 "Use the known outbound-network selector to graph connections to raisinkanes.com and show who's behind each IP" Basic source fallback -> filter -> Lift_To_Graph -> enrich -> fold -> render

AzureCrest (raw KQL -> Lift_To_Graph)

# Ask This What It Does
1 "Given `Email take 400`, create a graph showing email flow between senders and recipients"
2 "Graph emails in AzureCrest and collapse messages by verdict" Email mapping -> Graph_Fold_By_Property("EmailMessage", "verdict")
3 "Given `AuthenticationEvents take 200`, create a Lift_To_Graph visualization of users authenticating to hosts"
4 "Show IPs connecting to hosts through auth events in AzureCrest, with user nodes" 4-entity auth mapping: SrcIp -> AuthEvent -> Host + User
5 "Show process execution trees for hosts running powershell in AzureCrest" Raw ProcessEvents -> Process -> Parent + Host + User
6 "Graph outbound network connections from IPs to domains in AzureCrest" Raw OutboundNetworkEvents -> IP -> Domain mapping
7 "Create a graph of file creation events in AzureCrest showing users, files, and hosts" Raw FileCreationEvents -> User + File + Host mapping
8 "Graph DNS lookups in AzureCrest and fold IPs by domain" PassiveDns -> IP -> Domain mapping -> fold by domain

Source: SKILL.md on GitHub

1 warning1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill facilitates the transformation of Kusto Query Language (KQL) results into visual graphs within Kusto Explorer. It includes capabilities for generating KQL function deployment scripts and PowerShell scripts to automate the launch of the desktop application. These features include explicit security warnings and require user confirmation to ensure safe operation within the developer's environment.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 4d0badd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "1.2.1"
}

README badge

README badge for microsoft/skills/azure-kusto-irql-graph