All skills
microsoft avatar

/azure-kusto-irql

@4d0badd
by microsoftmicrosoft/skills3.1k stars
351

Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. Translates natural language hunting questions into composable IRQL pipelines using Get_*, Extract_*, and Enrich_* functions. WHEN: IRQL query, security hunt, threat hunting KQL, incident response query, compose hunting pipeline, failed logins, phishing investigation, lateral movement, process execution, file creation events.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-kusto-irql

This session only. Nothing lands on disk.

referencesEXAMPLES.md

≈571 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Try It Out -- azure-kusto-irql

Paste any of these into Copilot Chat to see the skill in action. Cluster: https://kc7001.eastus.kusto.windows.net


ValdyTimes (IRQL functions: Get_*, Extract_*, Enrich_*)

# Ask This What It Does
1 "Find all failed logins in ValdyTimes" Basic Get_Event_Authentication with filter
2 "Which sender domains are emailing executives?" Get_Email -> Extract_Email_Sender_Domain -> Enrich_Username_Employee
3 "Show me users with more than 20 failed logins and their job roles" Get_Event_Authentication -> summarize -> Enrich_Username_Employee
4 "Find powershell or rundll32 execution on any host" Get_Event_Process with command-line filter
5 "What domains are being accessed by IPs with failed logins?" Auth -> distinct IPs -> Enrich_Ip_Domain
6 "Find authentication from external IPs" Get_Event_Authentication_All with RFC1918 exclusion
7 "A file called Raisin_Kane appeared on some hosts. What processes ran on those hosts?" Get_Event_FileCreation_All -> victim hosts -> Get_Event_Process
8 "Which users are logging in from the most distinct IPs?" Get_Event_Authentication_All -> summarize dcount(ClientIp) by Username

AzureCrest (raw KQL — no IRQL)

AzureCrest has no IRQL functions. In this environment, route to the azure-kusto skill to author raw KQL equivalents (do not use azure-kusto-irql).

# Ask This What It Does
1 "Find all failed logins in AzureCrest" Raw AuthenticationEvents with result filter
2 "Which sender domains are emailing executives in AzureCrest?" Email -> extract domain -> join Employees
3 "Show users with more than 20 failed logins and their roles in AzureCrest" AuthenticationEvents -> summarize -> join Employees
4 "Find powershell execution across all hosts in AzureCrest" ProcessEvents with process_commandline filter
5 "What domains are accessed by IPs with failed logins in AzureCrest?" AuthenticationEvents -> distinct src_ip -> join PassiveDns
6 "Find authentication from external IPs in AzureCrest" AuthenticationEvents with RFC1918 exclusion

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides specialized capabilities for composing Kusto-based security hunting queries. It includes security considerations related to the automated generation of PowerShell scripts for local file management and the handling of sensitive security log data, such as authentication hashes. These features are aligned with the skill's purpose for incident response and include specific guidance to minimize potential risks.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 4d0badd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "1.2.1"
}

README badge

README badge for microsoft/skills/azure-kusto-irql