Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.
Installs into .claude/skills of the current project.
Are you the author of Cyber Analyzing Azure Activity Logs For Threats?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/nexuslinkproductions-cyber-analyzing-azure-activity-logs-for-threats)
---
name: cyber-analyzing-azure-activity-logs-for-threats
description: "Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections."
hide: true
---
<!-- GENERATED:YURI-CODEX-SKILL-ADAPTER:v1 -->
# YURI skill adapter
Authoritative source: `.claude/skills/cyber-analyzing-azure-activity-logs-for-threats/SKILL.md`
Authoritative source SHA-256: `f52b90e1edfece6020e30df6acae43100bafe0d0ed402030b3445c293f2b9f01`
Source class: `cyber-armed`
Before acting, read the authoritative source file above completely from beginning to end. If the governed source is absent, run `node _SYSTEM/Scripts/skill-recall.mjs --show cyber-analyzing-azure-activity-logs-for-threats` and read its complete verified output. Follow that source as the skill body; this adapter is a non-authoritative metadata-and-pointer projection.