An open-source framework called "security-investigator," which automates security investigations through natural language by combining Microsoft Sentinel, Defender XDR, and GitHub Copilot, has been published on GitHub .
Open Source · Agentic SOC Tooling
Investigate Microsoft Sentinel & Defender XDR in Plain English
"security-investigator" is a free, local-first framework that wires GitHub Copilot to Sentinel and Defender XDR via MCP — letting analysts run threat hunts, IOC checks and reports through natural-language prompts inside VS Code.
25
Specialized Agent Skills (threat-pulse, IOC, user & incident investigation)
9
Domains swept by the recommended "Threat Pulse" first scan
Free
Open source (Sentinel/Defender licenses & Copilot subscription required)
Connector Layer · Model Context Protocol
6 Official MCP Servers
Sentinel Data Lake / Exposure Graph · Graph API · Defender XDR Triage · KQL Search · Microsoft Learn · Azure MCP Server
3 Local MCP Apps
Geomap · Heatmap · Incident Comment
Prompt → Investigation Flow
Natural-language prompt"Investigate user@domain for 7 days"
→
Copilot + MCP tool callsKQL, Graph, IP enrichment
→
Prioritized HTML reportverdicts & recommended actions
Threat Pulse — Color-Coded Verdicts
Findings are triaged by severity so analysts know what to act on first.
What developers praise
End-to-end KQL, enrichment & reporting in natural language
Practical Threat Pulse prioritization
Local-first design keeps control on the analyst's machine
Adoption hurdles
MCP server setup (issuing a GitHub PAT)
Building the Python environment
Granting Sentinel & Graph API access permissions
Limited long-term production evaluation so far
Continue reading The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.
Already purchased? Sign in ✓ Signed in — this article isn’t included in your current plan.Unlocking the full article…