analyzing-office365-audit-logs-for-compromise

mukul975/analyzing-office365-audit-logs-for-compromise · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.8 KB
  • 📁scripts
  • ⚙️agent.py 9.8 KB
  • 📄LICENSE 11.0 KB

Related

  1. detecting-email-account-compromise · mukul975 bundle
    Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.
    24.6k
    repo stars
  2. competition-mailbox-abuse · zhaoxuya520 bundle
    Trace mailbox abuse chains including OAuth consent, forwarding rules, delegate access, and message rerouting in a CTF sandbox environment.
    12.8k
    repo stars
  3. detecting-email-forwarding-rules-attack · mukul975 bundle
    Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks.
    24.6k
    repo stars
  4. detecting-suspicious-oauth-application-consent · mukul975 bundle
    Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.
    24.6k
    repo stars
  5. email-security · zhaoxuya520 bundle
    Analyzes email security including phishing dissection, SPF/DKIM/DMARC authentication checks, BEC fraud patterns, and OAuth token abuse research for authorized reviews.
    12.8k
    repo stars
  6. detecting-business-email-compromise · mukul975 bundle
    Detect business email compromise (BEC) attacks using email gateway rules, behavioral analytics, and financial process controls.
    24.6k
    repo stars

Frequently asked questions

How do I install the analyzing-office365-audit-logs-for-compromise skill?

Run npx skillmds add mukul975/analyzing-office365-audit-logs-for-compromise in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the analyzing-office365-audit-logs-for-compromise skill do?

Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise. It is listed under Security, Incident Response on SkillMD.

Is analyzing-office365-audit-logs-for-compromise safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with analyzing-office365-audit-logs-for-compromise?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is analyzing-office365-audit-logs-for-compromise free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published analyzing-office365-audit-logs-for-compromise?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.