Works with the AI tools you already use
azure activity logs threat analysis
Analyze Azure logs, build KQL hunting queries, and generate SOC-ready threat reports for cloud environments.
$15
azure activity logs threat analysis
Example session with this skill installed
Analyze these AzureActivity log exports from the last 24 hours. I suspect unauthorized privilege escalation in the production subscription. Provide a hunting report and KQL for validation.
- Read your context and instructions
- Compiled the azure activity logs
- Generated the document
I have analyzed the provided AzureActivity logs for the production subscription over the last 24 hours. The analysis focused on administrative role assignments and high-impact control plane changes.
Azure Activity Log Threat Analysis Report
| Finding | Evidence / Operation | Actor | Impact | Confidence |
|---|---|---|---|---|
| Suspicious Role Assignment | Microsoft.Authorization/roleAssignments/write | svc_deploy@contoso.com | Owner permissions granted to a new service principal. | High |
| MFA Requirement Bypass | Update user (conditional access modification) | admin_hunter@contoso.com | Reduced security posture for privileged accounts. | Medium |
| Key Vault Access Change | Microsoft.KeyVault/vaults/accessPolicies/write | svc_deploy@contoso.com | Potential secret exfiltration capability. | High |
Validation KQL Queries
// Search for new Owner or Contributor assignments in the last 24 hours
AzureActivity
| where TimeGenerated > ago(24h)
| where OperationNameValue == "Microsoft.Authorization/roleAssignments/write"
| extend Properties_d = parse_json(Properties)
| extend RoleDefinition = tostring(Properties_d.roleDefinitionId)
| where RoleDefinition contains "8e3af657-a8ff-443c-a75c-2fe8c4bcb635" // Owner Role
| project TimeGenerated, Caller, RoleDefinition, ResourceGroup, _ResourceId
Detection Gaps
- Gap: No active alert for 'Owner' role assignments outside of known PIM windows.
- Gap: Lack of correlation between Service Principal creation and immediate permission assignment.
Next steps
- Verify if
svc_deploy@contoso.comwas part of a scheduled deployment. - Review the audit logs for
admin_hunter@contoso.comto check for session hijacking signs. - Implement the provided KQL as a scheduled analytic rule in Microsoft Sentinel.
azure-activity-logs-threat-analysis.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Security teams often struggle to parse through massive volumes of Azure Activity and Entra ID logs during incidents. Manually writing complex KQL queries while under pressure leads to missed indicators of compromise or inaccurate threat assessments.
What it does
- Generates KQL threat hunting queries for Azure control plane, identity, and Key Vault activity.
- Analyzes provided log exports to identify suspicious administrative changes and privilege escalation attempts.
- Produces structured threat hunting reports and incident support summaries based on evidence.
- Maps findings to MITRE ATT&CK techniques and identifies detection gaps in current monitoring.
- Converts log analysis into tool-agnostic detection logic or platform-specific SIEM content.
Frameworks & tools
Azure Activity Logs, Microsoft Entra ID (Azure AD), Kusto Query Language (KQL), Azure Log Analytics, and Azure Monitor.
Why this beats prompting it yourself
Standard LLM prompts often hallucinate KQL schemas or suggest offensive techniques. This skill enforces defensive boundaries, ensures schema accuracy for specific tables like SigninLogs or AzureDiagnostics, and follows a structured SOC-ready reporting methodology that separates facts from hypotheses.
Use cases
- Investigating a suspected credential theft via Entra ID sign-in anomaly logs.
- Building a detection gap register for a new Azure subscription deployment.
- Creating a timeline of administrative operations during a cloud security audit.
- Developing custom KQL alerts for unauthorized Network Security Group changes.
Known limitations
Requires authorized log data or specific workspace context to be useful. Does not perform live tenant interrogation without pre-configured access and credentials.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install
Needs access to