Alfonce27

SOC Investigation Toolkit — DevOps skill for Claude Code

DevOps community

SOC/IR toolkit for Microsoft Sentinel, Defender XDR, Entra and Purview, with CrowdStrike, Slack and Azure DevOps ingest, offline triage pipelines, and Claude Code hunting skills.

How to install SOC Investigation Toolkit

This entry records only its repository, not the path inside it, so there is no exact command to give. Open Alfonce27/SOC_Investigation_Toolkit and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What SOC Investigation Toolkit does

SOC/IR toolkit for Microsoft Sentinel, Defender XDR, Entra and Purview, with CrowdStrike, Slack and Azure DevOps ingest, offline triage pipelines, and Claude Code hunting skills. Includes an enterprise deployment guide.

Alternatives in DevOps

README

SOC Investigation Toolkit

Python and Go tooling plus Claude Code skills for a Security Incident Response (SIR) / SOC team's acquisition, triage, hunting and hand-off workflows against a Microsoft-centric estate (Sentinel, Defender XDR, Entra ID, Purview) with adjacent sources (CrowdStrike Falcon, Slack, Azure DevOps, Salesforce Experience Cloud, AWS CloudTrail).

The repo is structured so an analyst can `git clone` it once and reach a working end-to-end **acquire → triage → hunt → hand off** loop in under 30 minutes. Each tool is self-contained under `tools/`; each in-repo Claude skill lives under `skills/`; repo-wide setup and hygiene helpers live under `scripts/`; engineering-only surface is quarantined under `engineering/`.

**First time here?** Read [`docs/ANALYST-ONBOARDING.md`](docs/ANALYST-ONBOARDING.md) — the 30-minute guided first run (install, auth, one worked example).

**Deploying for a team?** Read [`docs/ENTERPRISE-SETUP.md`](docs/ENTERPRISE-SETUP.md) — identity, RBAC, least-privilege API clients, secrets, CI and rollout.

**Want the map before the manual?** Open [`docs/workflows.html`](docs/workflows.html) in any browser (no install, opens from `file://`) for a one-page visual of how the tools, skills and shared scripts fit together. Generated from `docs/workflows_manifest.json`.

**Provenance.** This is a sanitized public release of an internal toolkit. Sprint planning history, worklogs and all case-derived fixtures were removed; every identifier in this repo is a documented placeholder (`example.com`, `contoso.onmicrosoft.com`, RFC 5737 IPs, all-zero GUIDs).


Design principles

  • Read-only by construction. Every ingest tool runs a scope preflight and refuses to start if its token carries a write, manage, admin or create scope (exit code 8). Missing scope lists fail closed. The MCP server only exposes read-only KQL.
  • Evidence never lives in the repo. Durable case state lives off-repo under `~/SI