惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

www.infosecurity-magazine.com
www.infosecurity-magazine.com
aimingoo的专栏
aimingoo的专栏
博客园 - 叶小钗
Jina AI
Jina AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
人人都是产品经理
人人都是产品经理
博客园_首页
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
云风的 BLOG
云风的 BLOG
腾讯CDC
V
Visual Studio Blog
宝玉的分享
宝玉的分享
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
P
Palo Alto Networks Blog
Know Your Adversary
Know Your Adversary
NISL@THU
NISL@THU
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
I
InfoQ
Simon Willison's Weblog
Simon Willison's Weblog
H
Help Net Security
AWS News Blog
AWS News Blog
P
Proofpoint News Feed
月光博客
月光博客
T
Threatpost
Recent Announcements
Recent Announcements
G
Google Developers Blog
Security Latest
Security Latest
T
Threat Research - Cisco Blogs
Blog — PlanetScale
Blog — PlanetScale
A
Arctic Wolf
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Latest news
Latest news
T
The Exploit Database - CXSecurity.com
Security Archives - TechRepublic
Security Archives - TechRepublic
Google DeepMind News
Google DeepMind News
Google DeepMind News
Google DeepMind News
V
V2EX
P
Proofpoint News Feed
Y
Y Combinator Blog
The Register - Security
The Register - Security
N
News | PayPal Newsroom
L
Lohrmann on Cybersecurity
H
Hacker News: Front Page
MongoDB | Blog
MongoDB | Blog
量子位
T
Troy Hunt's Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Recent Commits to openclaw:main
Recent Commits to openclaw:main

rss.livelink.threads-in-node

Probably has less bugs than windows 11 | Microsoft Community Hub Quick question about window PC requirements for meta link cable? Is it possible to run ryujinx canary on an administrator account on windows? Why Windows 11 still depends on 1990s code iphone auf pc spiegeln windows 11 – Welche Methode funktioniert zuverlässig? CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection Known issue: Upgrading Microsoft Tunnel version 20260129.1 What's New in Microsoft Entra: May 2026 Carta de validación TSP (aka.ms/TSP_Achievement_Code_Enroll...) restricted across all accounts unable to enroll Class Admin Build observability for scalable AI apps and agents selling through Microsoft Marketplace Inspektor Gadget Completes Its First Independent Security Audit Retirement of Direct Exchange ActiveSync Certificate-Based Authentication by End of 2026 Export mixed text and tabular Excel to PDF Safely Migrating Terraform Managed Disks on Azure Using Stable Keys and Copilot Microsoft 365 & Power Platform Community call Microsoft 365 & Power Platform product updates call Course Retirement Announcement: AI-3022 The End is Nigh for DES and an Update for hunting down RC4 Unable to Access Scheduling Poll Options Title Plan Update - May 8, 2026 Secure Medallion Architecture Pattern on Azure Databricks (Part II) From Observability to Action: Building an AI-Powered AIOps Agent for Customer-Specific Operations General Availability of Mailbox Import and Export Microsoft Graph APIs Why External Participants Can—or Can’t—Join a Microsoft Teams Meeting CRITICAL: Data Loss on Build 26200.8328 - AI Storage Sense deleted 160+ apps with 870GB free space. Why is everyone hating on Windows 11? I was pissed at the Windows 11 context menu so I built this. Windows 11 Shows ASUS LOGO but then goes dark for 5 minutes Windows 11 causes discrete graphics cards to be locked at their base clock speed when idle In Windows 11 Insider Preview 26300.8346, the Start button is offset to the left and misaligned The Windows 10 update failed, so I'm planning to switch to Windows 11 Using the Microsoft Graph PowerShell SDK to Update User Profiles Someone please help me - Windows Insider Program How to Reduce No-Shows for WooCommerce Appointments Windows 11 Insider Program Download Update Beta Channel stuck at 99% How to transfer photos from iphone to pc on Windows 11 without itunes Windows 11 Dell Laptop Latitude 5500 New PC won’t boot up windows 11 Fresh Windows Install – Driver/Service Advice for G14 (2021 R9 5900HS + RTX 3050 Ti) AD Recycle Bin – “The specified value already exists” but Recycle Bin is non‑functional Why deleting files does not free up space on mac How to delete or clear cache on macbook air automatically Announcing Microsoft Host Integration Server 2028: Modern connectivity for IBM Mainframes Midranges From Test Cases to Trust: Elevating Enterprise Quality with GitHub Copilot Bootfähigen usb stick erstellen am mac für Windows 11? My modpack has this error and I can't find the cause Where is the option to attach file for parent Income Statement Form? Watching streamers with 2k resolution enabled makes my PC lag Update Your Exchange SE Hybrid On-premises Rich Coexistence to Graph Partner Blog | Unlock the cloud benefits in your partner benefits package with a streamlined activation experience Turn your Azure commitments into smarter cloud investments with Microsoft Marketplace Drive stronger Microsoft alignment and unlock co-sell growth at Ultimate Partner LIVE RECAP: Microsoft Elevate Partner Community Monthly Call - May 2026 Public Preview: Migrate your regional virtual machines to availability zones Security Dashboard for AI: 3 Ways CISOs Drive Impact Today PLANNER WILL NOT PUBLISH THE SCHEDULES FOR MY PLANS, BY CREATING AN iCALENDAR LINK....HELP | Microsoft Community Hub Firm AI for professional services: governed, agentic workflows built on Microsoft Azure Azure Incident Retrospective - Please register! Session 2 - Tracking ID: 5GP8-W0G Azure Incident Retrospective - Please register! Session 1 - Tracking ID: 5GP8-W0G Autoruns, ProcDump, ZoomIt, DebugView, NotMyFault, ProcExp, Procmon, and Linux tools Edge Canary not auto updating? Edge Dev on Windows - Tab sync not working Available today: GPT-5.5 Instant in Microsoft 365 Copilot Introducing the Azure Resource Manager MCP Server! Defender Threat & Vulnerability Management Reporting A New Chapter for Realtime AI: Reasoning, Translation, and Real-Time Transcription Plan a fun Family Wellness Month with Copilot Released: May 2026 Exchange Server Hotfix Update Service Bus SBMP Retirement: What BizTalk Server 2020 Customers Need to Know Azure Incident Retrospective Please register for one of the 2 sessions below! Planner Agent brings work management directly into Microsoft 365 Copilot Local account and MS account Cannot reset account password Announcing Windows Admin Center: Virtualization Mode Public Preview 2! Azure RBAC Custom Role Best Practices or Common Build Patterns Pivot Table Data Centering How to design production-ready AI architectures for apps and agents on Microsoft Marketplace Troubleshoot with OpenTelemetry in Azure Monitor - Public Preview Secure, Keyless Application Access with Managed Identities - Now GA in Azure Files SMB Help shape the Microsoft 365 Copilot community experience — your input matters Microsoft 365 Security Best Practices for Enterprises Running multimedia AI models on Container Apps with Serverless GPU (A100 & T4) SharePoint List Migration to new Tenant Windows 11: Task Manager: Background Processes: Stop Unnecessary Ones from Starting Automatically Detecting Plain‑Text Password Exposure Using Custom Regex in Microsoft Purview MVP Enthusiast Effective, engaging events in communities and storylines Change Optics Report released into Public Preview to showcase messages impacted by future changes RECAP: Microsoft Elevate Partner Community Monthly Call - April 2026 | Microsoft Community Hub Networking in Windows Server 2025 - Windows Server Summit Want to get more out of Microsoft Copilot Chat without adding another tool—or cost—to your stack? Announcing Public Preview: Security Copilot’s Email Summary in Microsoft Defender Copilot Chat in financial services: Is productivity moving faster than policy? How manufacturers can scale AI from pilot to production with Microsoft Marketplace SSO for a Python Teams Bot (M365 Agents SDK + FastAPI) — Single-Tenant, Multi-Tenant, and UAMI | Microsoft Community Hub Advice required for temp / agency staff | Microsoft Community Hub 'You've tried to sign in too many times with incorrect account/password' | Microsoft Community Hub When will Windows 11 natively support Auracast broadcasting? | Microsoft Community Hub Authenticator | Microsoft Community Hub
Build a Local Microsoft Sentinel Triage Agent in VS Code (Copilot + MCP)
absharan · 2026-05-18 · via rss.livelink.threads-in-node

Modern SOC work is not limited by data—it’s limited by the friction of collecting it. This post shows a local-first workflow that lets you investigate Microsoft Sentinel incidents from inside VS Code using GitHub Copilot Chat for reasoning and a small, deterministic MCP toolset for evidence retrieval and (optionally) approval-gated writeback.

What you’ll take away:

  • How to structure a Copilot + MCP triage loop that stays grounded in Azure evidence
  • A reliability pattern: fall back to KQL when Sentinel subresource APIs are flaky
  • A safety pattern: draft-first, explicit-approval writeback for incident comments

Sentinel triage is powerful but fragmented: you jump between the portal, KQL, entity pivots, and case notes just to answer “what happened?” The goal here is to collapse that into a single, repeatable loop inside the editor.

  • Resolve the incident and pull the underlying alerts/entities
  • Pivot into AzureActivity (and other logs) to identify the actor and outcome
  • Use threat intelligence (TI) for context—not as the decision
  • Generate an evidence-backed narrative and draft comment; write back only on explicit approval
  • Evidence first: every claim must be traceable to Sentinel APIs or Log Analytics results
  • Small tool surface: fewer tools, clearer prompting, easier hardening
  • Reliability by design: if one API path fails, pivot to KQL and continue
  • Safety boundary: investigation and writeback are separate, and writeback is approval-gated

A local TypeScript MCP server exposes a handful of triage tools to Copilot Chat in VS Code. Reads come from Sentinel + Log Analytics; writes (incident comments) are optional and require explicit approval.

  • Copilot Chat (VS Code) decides the next step and summarizes outputs
  • MCP server executes allowed tools: incident lookup, alert/entity retrieval, KQL queries, optional comment writeback
  • Evidence sources: Sentinel Incident APIs + Log Analytics tables (SecurityIncident, SecurityAlert, AzureActivity, TI tables)
  • Safety gate: writeback happens only after explicit approval; otherwise you get a draft

MCP is useful here because it separates reasoning from execution: Copilot can decide what to do, but only the MCP server can do it—and only through tools you explicitly define and can audit.

  • list_incidents / get_incident (ground the case)
  • get_incident_alerts / get_incident_entities (fast path)
  • run_incident_kql (reliable fallback + pivots)
  • add_incident_comment (draft-first; writes only with approval)
sentinel-triage-local Investigate Sentinel incident 1478 end to end in workspace Subscription ID/Resource Group/Workspace Name. Resolve the incident ID first, collect underlying alerts and entities, enrich with AzureActivity and TI, determine whether the activity is malicious or benign, and return:
1. Investigation summary
2. Key evidence
3. Entity analysis
4. TI enrichment result
5. Risk assessment
6. Recommended disposition
7. Final incident comment draft
Rules:
- Use tool output only, no guessing.
- If alert/entity subresource APIs fail, pivot to KQL and continue.
- Do not submit the comment unless I explicitly say: APPROVE COMMENT.

Resolve the human-friendly incident number to the Sentinel incident resource ID, then capture the metadata you need to drive every later pivot.

Incident numbers are convenient for analysts, but the actual investigation flow depends on the underlying incident resource ID. Resolving that first gives the workflow a concrete anchor for:

  • Title
  • Severity
  • Owner
  • Status
  • Alert count
  • Analytic rule IDs
  • Incident URL

This gives you the stable identifiers (and the URL) needed to retrieve alerts, entities, and supporting logs.

Pull the alerts behind the incident and the entities they reference. When the incident subresource APIs behave, this is the fastest way to assemble the working set.

In the ideal path, the agent can call the incident alert and entity subresources directly. That gives fast access to:

  • Alert IDs
  • Alert names
  • Timestamps
  • Severities
  • Entities
  • Provider metadata

In real environments, the incident subresource APIs for alerts/entities are not always dependable. When they fail, the workflow switches to Log Analytics and reconstructs the same evidence via KQL—so the investigation continues.

  • SecurityIncident to recover the incident record and alert IDs
  • SecurityAlert to retrieve alert details and entities
  • AzureActivity to determine who or what performed the operation
  • ThreatIntelligenceIndicator and ThreatIntelIndicators for enrichment

In the incidents I tested, AzureActivity was the fastest way to classify “suspicious deployment” alerts: it tells you who did the action, what operation ran, and whether it succeeded.

The evidence showed:

  • The caller was a single Microsoft Entra ID object ID
  • Claims_d.idtyp = "app"
  • Authorization_d.evidence.principalType = "ServicePrincipal"
  • The activity was tied to a policy assignment
  • The operation was MICROSOFT.RESOURCES/DEPLOYMENTS/WRITE
  • The result was BadRequest with InvalidTemplate

That pattern typically points to automation (service principal + policy-driven deployment) failing due to a bad template—not an interactive attacker.

Enrich observables against TI, but treat it as corroboration: a hit is not proof, and a miss is not a clean bill of health. In my test runs, TI mainly helped refine confidence after AzureActivity and alert evidence established the likely story.

Once the tools return results, Copilot’s job is synthesis: turn structured evidence into a short narrative an analyst can paste into the case.

  • What happened, who/what triggered it, and whether it succeeded
  • Key supporting evidence (alerts, entities, AzureActivity pivots, TI context)
  • A recommended disposition and a draft incident comment

Incident comment written back automatically (after approval) (screenshot):

The agent can draft a comment automatically, but it cannot change incident state unless the analyst explicitly approves. That boundary is what makes the workflow usable in real operations.

After approval, the tool submits the drafted comment directly to the Sentinel incident so the portal reflects the same evidence-backed narrative.

  • Default: return the draft comment only
  • On approval: acquire an ARM token via Azure CLI and submit via curl.exe (hardened with validation + retries)
  • Less context switching: investigation happens where you already work
  • More consistency: the same loop runs every time, with deterministic tools
  • Better classification: AzureActivity pivots reduce false “user did X” assumptions
  • Safer automation: drafts are automatic; writes are explicit and auditable

AI is most useful in a SOC when it is constrained: deterministic tools fetch the evidence, the model synthesizes it, and humans keep control of state changes. A local Copilot + MCP workflow hits that sweet spot—faster triage for the SOC analysts.