By dstreefkerk
Microsoft Sentinel skills — Codeless Connector Framework, KQL expertise, ARM template generation, and use case documentation.
Use before writing any Microsoft Sentinel connector ARM template, DCR, KQL transform, or createUiDefinition.json. Provides the complete CCF (Codeless Connector Framework) reference for RestApiPoller, Push, and GCP connector types — including escaping rules, authentication, pagination, UI definitions, and deployment gotchas. Also use when debugging connector deployment failures or reviewing existing CCP templates.
KQL expert for Microsoft Sentinel, Azure Monitor, and M365 Defender. Use proactively when the user works with any .kql file, writes or reviews KQL queries, develops analytics or detection rules, performs threat hunting, needs DCR transformation KQL, or asks to optimise, validate, or convert a KQL query. Covers query optimisation, schema validation, ASIM normalisation, SPL migration, and best practices.
Generates deployment-ready Microsoft Sentinel Analytic Rule ARM templates from KQL detection queries. Use when the user asks to create, export, or package a Sentinel analytics rule, convert a KQL query into an ARM template, or generate rule deployment files with MITRE ATT&CK mappings and entity extraction.
Documents Microsoft Sentinel analytics rules as comprehensive SOC use cases. Use when the user wants to document a Sentinel rule, create SOC documentation, generate use case docs from an ARM template, or document a KQL detection query.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Personal Claude Code plugins following the Agent Skills specification for broad compatibility.
| Plugin | Skill | Description |
|---|---|---|
powershell | powershell | Enterprise PowerShell coding standards — structure, error handling, security, performance, and output patterns |
sentinel | codeless-connectors | Complete CCF reference for building Sentinel REST/Push/GCP connector ARM templates, DCRs, KQL transforms, and UI definitions |
kql-expert | KQL query optimisation, schema validation, and best-practice compliance for Sentinel and M365 Defender detection rules | |
sentinel-arm-generator | Generates deployment-ready Sentinel Analytic Rule ARM templates from KQL queries with MITRE mappings and entity extraction | |
sentinel-use-case-documentor | Documents Sentinel analytics rules as comprehensive SOC use cases from ARM templates or KQL detection queries | |
cyber | cyber-impact-statement | CISO-level impact statements for security control failures — direct causality, business outcomes, no corporate fluff |
tech-researcher | research | Validated technical research pipeline with parallel data gathering, quality-gated critique (8/10 threshold), and automatic revision loop |
reflect | reflect | Session review — identifies mistakes, friction, and skill optimisation opportunities |
productivity | slide-notes | Structured speaker notes for technical presentations — runbook-style bullets with Q&A, references, timing cues, and transitions |
stream-transcript | Extracts WebVTT transcripts and detects slide transitions from Microsoft Stream / SharePoint-hosted video recordings |
/plugin marketplace add dstreefkerk/claude-skills
Then install individual plugins:
/plugin install powershell@dstreefkerk-skills
/plugin install sentinel@dstreefkerk-skills
/plugin install cyber@dstreefkerk-skills
/plugin install tech-researcher@dstreefkerk-skills
/plugin install reflect@dstreefkerk-skills
/plugin install productivity@dstreefkerk-skills
claude --plugin-dir ./plugins/sentinel
npx claudepluginhub dstreefkerk/claude-skills --plugin sentinelValidated technical research pipeline with parallel data gathering, quality-gated critique (8/10 threshold), and automatic revision loop.
Productivity skills — PowerPoint speaker notes for technical presentations, and Microsoft Stream transcript extraction with slide detection.
Session reflection — review mistakes, friction, and skill optimization opportunities at session end.
Enterprise PowerShell coding standards and best practices.
CISO-level cyber GRC impact statements for security control failures with direct causality and business outcomes.
Security operations including SIEM rule design, detection engineering, vulnerability management, security monitoring, and threat intelligence integration.
Cybersecurity skills for AI agents — code audit, cloud, recon, IR, AI security, and more
Assist with security incident response
A curated collection of production-ready agentic skills for Microsoft Azure development. Installs 193+ skills covering Azure compute, data, AI/ML, networking, security, and management services. Built from Microsoft Learn documentation and following the Agent Skills open standard.
Develop, optimize, and troubleshoot CrowdStrike LogScale security detection queries using CQL — includes case statements, multi-event correlation, investigation playbooks, and hunting rules.
872 on-demand security skills for CTF, pentest, bug bounty, DFIR, detection engineering, cloud, identity, and red/blue team work. Skills are plain Markdown and activate by task without permanently consuming context. Bundles vendored skills under mixed licenses (MIT, Apache-2.0, CC-BY-SA-4.0) — see per-source attribution in .claude/skills/SKILLS.md.