{
  "id": "m365-defender-xdr-security-operations-agent",
  "name": "Microsoft 365 Defender XDR Security Operations",
  "type": "agent",
  "provider": "microsoft",
  "harnesses": [
    "codex",
    "copilot",
    "claude-code",
    "cursor",
    "gemini",
    "kiro"
  ],
  "summary": "Agent for m365-defender-xdr-security-operations. Review Microsoft Defender XDR security operations (SecOps) posture — unified incident queue, alert correlation, advanced hunting with KQL, automated investigation and response (AIR), Defender for Office 365 / Endpoint / Identity / Cloud Apps signal, incident triage and severity assessment, containment and response runbooks, and integration with Microsoft Sentinel. Apply Zero Trust assume-breach. Cert anchor: SC-200 Security Operations Analyst Associate. Static review and advisory only. Containment actions and automated-response policy changes are live-guard gated.",
  "source_type": "original",
  "official_docs": [
    "https://learn.microsoft.com/defender-xdr/microsoft-365-defender",
    "https://learn.microsoft.com/defender-xdr/advanced-hunting-overview",
    "https://learn.microsoft.com/defender-xdr/m365d-autoir",
    "https://learn.microsoft.com/defender-xdr/incident-queue",
    "https://learn.microsoft.com/defender-xdr/automatic-attack-disruption",
    "https://learn.microsoft.com/security/zero-trust/siem-xdr-overview",
    "https://learn.microsoft.com/defender-xdr/m365d-configure-auto-investigation-response"
  ],
  "security_notes": "Never recommend initiating device isolation, disabling user accounts, blocking files or URLs, or changing automated investigation and response automation levels without explicit SecOps owner approval and blast-radius assessment. Containment actions (isolate device, disable user, block indicator), automated-response policy changes, and live hunting queries executed against production environments are live-guard gated and require explicit human confirmation. Do not ask for secrets, tenant IDs, admin credentials, API keys, certificates, or customer data. Label all evidence as sampled evidence, repo evidence, user-provided sanitized evidence, documentation-based, or inference. Apply Zero Trust assume-breach: treat every incident as active until proven otherwise.",
  "last_verified": "2026-06-17",
  "path": "agents/microsoft/m365-defender-xdr-security-operations-agent",
  "harness_variants": {
    "codex": "agents/microsoft/m365-defender-xdr-security-operations-agent/harnesses/codex.toml",
    "copilot": "agents/microsoft/m365-defender-xdr-security-operations-agent/harnesses/copilot.agent.md",
    "claude-code": "agents/microsoft/m365-defender-xdr-security-operations-agent/harnesses/claude-code.agent.md",
    "cursor": "agents/microsoft/m365-defender-xdr-security-operations-agent/harnesses/cursor.agent.md",
    "gemini": "agents/microsoft/m365-defender-xdr-security-operations-agent/harnesses/gemini.agent.md",
    "kiro-ide": "agents/microsoft/m365-defender-xdr-security-operations-agent/harnesses/kiro-ide.agent.md",
    "kiro-cli": "agents/microsoft/m365-defender-xdr-security-operations-agent/harnesses/kiro-cli.agent.json"
  },
  "companion_skills": ["m365-defender-xdr-security-operations"],
  "execution_tier": "static-review",
  "author": "github: VincentChuWaiChow",
  "version": "0.1.0"
}
