# io.github.trickyfalcon/mcp-msdefenderkql

> Use this tool when you need to analyze Microsoft Defender data using natural language queries, solving problems such as threat hunting and security incident response. It takes natural language input and executes KQL queries, outputting relevant data and insights from Microsoft Defender Advanced Hunting. Ideal for security professionals and analysts seeking to simplify their query process and gain quicker access to critical security information.

Canonical page: https://skillsregistry.net/skills/io-github-trickyfalcon-mcp-msdefenderkql  
JSON: https://api.skillsregistry.net/v1/skills/io-github-trickyfalcon-mcp-msdefenderkql

## Description

Execute KQL queries against Microsoft Defender Advanced Hunting via natural language.

## Trust

- **Trust score (0–1):** 0.30
- **Verification tier:** unverified
- **Last scanned:** 2026-08-23

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** other
- **Updated:** 2026-08-23

## Source

- **Source listing:** [MCP Registry](https://registry.modelcontextprotocol.io/v0/servers/io.github.trickyfalcon%2Fmcp-msdefenderkql)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "io-github-trickyfalcon-mcp-msdefenderkql"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/io-github-trickyfalcon-mcp-msdefenderkql` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/io-github-trickyfalcon-mcp-msdefenderkql/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
