Skip to content

feat: add Defender Scout KQL agent for Microsoft Defender Advanced Hunting#1021

Merged
aaronpowell merged 2 commits intogithub:stagedfrom
subhashisbhowmikicpes:add-defender-scout-kql-agent
Mar 16, 2026
Merged

feat: add Defender Scout KQL agent for Microsoft Defender Advanced Hunting#1021
aaronpowell merged 2 commits intogithub:stagedfrom
subhashisbhowmikicpes:add-defender-scout-kql-agent

Conversation

@subhashisbhowmikicpes
Copy link
Contributor

Agent: Defender Scout KQL 🛡️

Category: Security / Microsoft Defender

What This Agent Does

Specialized GitHub Copilot agent for generating, validating, and optimizing KQL queries across Microsoft Defender XDR Advanced Hunting. Covers Endpoint, Identity, Office 365, Cloud Apps, and Vulnerability Management tables.

Capabilities

  • Natural language to production-ready KQL query generation
  • Query syntax validation and error detection
  • Performance optimization for large dataset queries
  • Threat hunting query templates
  • Plain English explanations of complex queries

Supported Defender Tables

DeviceInfo, DeviceProcessEvents, DeviceNetworkEvents, EmailEvents, IdentityLogonEvents, CloudAppEvents, AlertInfo, DeviceTvmSoftwareVulnerabilities

Pre-loaded Prompts

  1. Generate Device Query
  2. Threat Hunting
  3. Vulnerability Check
  4. Alert Analysis
  5. Email Security
  6. Query Optimization
  7. Explain Query
  8. Identity Attacks

Source Repository

https://github.com/samikroy/ms-defender-scout (MIT License)

Testing

Tested in VS Code Copilot Chat and GitHub Web comment interface.

@aaronpowell aaronpowell enabled auto-merge (squash) March 16, 2026 21:40
@aaronpowell aaronpowell merged commit d95d532 into github:staged Mar 16, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants