{"repo":"SCStelz/security-investigator","free":true,"listed":false,"github":"https://github.com/SCStelz/security-investigator","clone":"git clone https://github.com/SCStelz/security-investigator.git","description":"Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.","language":"Python","stars":235,"topics":[],"license":"MIT","category":"security-tools","readme_excerpt":"🔒 Security Investigation Automation System Comprehensive, automated security investigations powered by Microsoft Sentinel, Defender XDR, Graph API, and threat intelligence — with 25 specialized Agent Skills 📺 Video Walkthrough: See this project in action — Watch on YouTube (starts at the Security Investigator demo). Covers the end-to-end workflow: natural language investigations, MCP server integration, KQL query execution, threat intelligence enrichment, and automated report generation. An investigation automation framework that combines GitHub Copilot , VS Code Agent Skills , and Model Context Protocol (MCP) servers to enable natural language security investigations. Ask questions like \"Investigate this user for the last 7 days\" or \"Is this IP malicious?\" and get comprehensive analysis with KQL queries, threat intelligence correlation, and professional reports. 🖥️ Also runs in the GitHub Copilot app (desktop) — ideal for scheduled automations (unattended Threat Pulse / Threat Intel Campaign runs). It uses a worktree-per-session model with a few setup differences from VS Code — see Running in the GitHub Copilot App. Quick Start (TL;DR) 🚀 Recommended first run: The Threat Pulse skill is the best starting point. It runs a broad-spectrum scan across 9 security domains (incidents, identity, endpoint, exposure, email, UEBA, auth spray, privileged ops, CVEs) and produces prioritized findings with color-coded verdicts (🔴 Escalate / 🟠 Investigate / 🟡 Monitor / ✅ Clear). Each ","default_branch":null,"files":null,"tree":[],"storefront":"/r/SCStelz","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/SCStelz/security-investigator/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}