detecting-email-account-compromise

mukul975/detecting-email-account-compromise · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.4 KB
  • 📁scripts
  • ⚙️agent.py 8.5 KB
  • 📄LICENSE 11.0 KB

Related

  1. conducting-phishing-incident-response · mukul975 bundle
    Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages, and remediating affected accounts.
    24.6k
    repo stars
  2. analyzing-office365-audit-logs-for-compromise · mukul975 bundle
    Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
    24.6k
    repo stars
  3. detecting-suspicious-oauth-application-consent · mukul975 bundle
    Detect risky OAuth application consent grants in Azure AD / Microsoft Entra ID using Microsoft Graph API, audit logs, and permission analysis to identify illicit consent grant attacks.
    24.6k
    repo stars
  4. post-exploiting-microsoft-graph-with-graphrunner · mukul975 bundle
    Perform reconnaissance, persistence, privilege escalation, and data pillaging on Microsoft 365/Entra ID tenants via the Microsoft Graph API using the GraphRunner PowerShell toolset.
    24.6k
    repo stars
  5. detecting-business-email-compromise · mukul975 bundle
    Detect business email compromise (BEC) attacks using email gateway rules, behavioral analytics, and financial process controls.
    24.6k
    repo stars
  6. hunting-saas-sso-token-abuse · mukul975 bundle
    Detect SSO and OAuth token replay and SaaS lateral movement using identity telemetry from Microsoft Entra ID and Okta.
    24.6k
    repo stars

Frequently asked questions

How do I install the detecting-email-account-compromise skill?

Run npx skillmds add mukul975/detecting-email-account-compromise in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the detecting-email-account-compromise skill do?

Detect compromised O365 and Google Workspace email accounts by analyzing inbox rule creation, suspicious sign-in locations, mail forwarding rules, and unusual API access patterns via Microsoft Graph and audit logs. It is listed under Security, Incident Response on SkillMD.

Is detecting-email-account-compromise safe to use?

SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with detecting-email-account-compromise?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is detecting-email-account-compromise free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published detecting-email-account-compromise?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.