SOC Investigation Toolkit — DevOps skill for Claude Code
SOC/IR toolkit for Microsoft Sentinel, Defender XDR, Entra and Purview, with CrowdStrike, Slack and Azure DevOps ingest, offline triage pipelines, and Claude Code hunting skills.
How to install SOC Investigation Toolkit
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open Alfonce27/SOC_Investigation_Toolkit and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What SOC Investigation Toolkit does
SOC/IR toolkit for Microsoft Sentinel, Defender XDR, Entra and Purview, with CrowdStrike, Slack and Azure DevOps ingest, offline triage pipelines, and Claude Code hunting skills. Includes an enterprise deployment guide.
Alternatives in DevOps
- CLAUDE.md CI/CD Wiki — Community patterns for CLAUDE.md configuration in CI/CD pipelines 22.3k ★
- Claude Code GitHub Actions — by Anthropic - Official GitHub Actions integration for Claude Code with examples and documentation for automat 6.4k ★
- Claudekit DevOps Tools — DevOps automation tools 1.9k ★
README
SOC Investigation Toolkit
Python and Go tooling plus Claude Code skills for a Security Incident Response (SIR) / SOC team's acquisition, triage, hunting and hand-off workflows against a Microsoft-centric estate (Sentinel, Defender XDR, Entra ID, Purview) with adjacent sources (CrowdStrike Falcon, Slack, Azure DevOps, Salesforce Experience Cloud, AWS CloudTrail).
The repo is structured so an analyst can `git clone` it once and reach a working end-to-end **acquire → triage → hunt → hand off** loop in under 30 minutes. Each tool is self-contained under `tools/`; each in-repo Claude skill lives under `skills/`; repo-wide setup and hygiene helpers live under `scripts/`; engineering-only surface is quarantined under `engineering/`.
**First time here?** Read [`docs/ANALYST-ONBOARDING.md`](docs/ANALYST-ONBOARDING.md) — the 30-minute guided first run (install, auth, one worked example).
**Deploying for a team?** Read [`docs/ENTERPRISE-SETUP.md`](docs/ENTERPRISE-SETUP.md) — identity, RBAC, least-privilege API clients, secrets, CI and rollout.
**Want the map before the manual?** Open [`docs/workflows.html`](docs/workflows.html) in any browser (no install, opens from `file://`) for a one-page visual of how the tools, skills and shared scripts fit together. Generated from `docs/workflows_manifest.json`.
**Provenance.** This is a sanitized public release of an internal toolkit. Sprint planning history, worklogs and all case-derived fixtures were removed; every identifier in this repo is a documented placeholder (`example.com`, `contoso.onmicrosoft.com`, RFC 5737 IPs, all-zero GUIDs).
Design principles
- Read-only by construction. Every ingest tool runs a scope preflight and refuses to start if
its token carries a write, manage, admin or create scope (exit code
8). Missing scope lists fail closed. The MCP server only exposes read-only KQL. - Evidence never lives in the repo. Durable case state lives off-repo under `~/SI
Related Skills
Certification Mock Exam
Claude skill that builds timed, offline HTML mock exams for professional IT certifications (Databricks, Micros
Azure DevOps
Manage Azure DevOps projects, repos, PRs, pipelines, and work items via REST API.
Ado PowerShell
An AI agent skill that enables GitHub Copilot, Claude Code, and other compatible agents to interact with the A
Azure
Azure identity (Workload Identity, OIDC, Entra ID), resource tagging, AKS platform patterns, RBAC scoping, and
Getting Started With DevOps AI Skills
Getting Started with DevOps AI Skills — a Pulumi workshop: build, share, and run Agent Skills with Microsoft A
Azure Research
Research Azure services and architecture patterns using Microsoft Learn MCP for authoritative guidance
Related Agents
Azure Infra Engineer
Use when designing, deploying, or managing Azure infrastructure with focus on network architecture, Entra ID i
Azure Architect
Expert Azure architecture guidance grounded in the Well-Architected Framework and current Microsoft docs. Use
Scope Investigate
SOC alert investigation assistant. Guides analysts through CloudTrail-based alert investigation in Splunk — st