bykillvxk· 108 skills
通过 azure-monitor-query 查询 Azure Monitor 活动日志和登录日志,检测可疑管理操作、不可能的地理旅行(Impossible Travel)、权限提升和资源修改。为 Azure 环境的威胁狩猎构建 KQL 查询。适用于调查可疑的 Azure 租户活动或构建云 SIEM 检测规则。
$npx -y skills add killvxk/cybersecurity-skills-zh --skill analyzing-azure-activity-logs-for-threatsInstalls into the current project.
Run `npx skills use "https://github.com/killvxk/cybersecurity-skills-zh" --skill "killvxk/cybersecurity-skills-zh/analyzing-azure-activity-logs-for-threats"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/killvxk/cybersecurity-skills-zh" that are relevant to the current task. Run `npx skills add "https://github.com/killvxk/cybersecurity-skills-zh"` and select the relevant skills, then follow their instructions.