investigating-phishing-email-incident

mukul975/investigating-phishing-email-incident · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Investigate phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 2.5 KB
  • 📁scripts
  • ⚙️agent.py 7.5 KB
  • 📄LICENSE 11.0 KB

Related

  1. performing-ioc-enrichment-automation · mukul975 bundle
    Automates multi-source enrichment of IPs, domains, URLs, and file hashes using VirusTotal, AbuseIPDB, Shodan, GreyNoise, URLScan.io, and MISP to provide contextual risk scoring and disposition recommendations for SOC analysts.
    24.6k
    repo stars
  2. building-phishing-reporting-button-workflow · mukul975 bundle
    Deploy a phishing report button in email clients and build an automated triage workflow that analyzes user-reported suspicious emails, extracts IOCs, and provides feedback to reporters.
    24.6k
    repo stars
  3. hunting-for-spearphishing-indicators · mukul975 bundle
    Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks.
    24.6k
    repo stars
  4. analyzing-indicators-of-compromise · mukul975 bundle
    Triages and enriches indicators of compromise (IPs, domains, file hashes, URLs, email artifacts) from phishing emails, security alerts, or threat feeds, assigning confidence scores and dispositions using VirusTotal, AbuseIPDB, MalwareBazaar, and MISP.
    24.6k
    repo stars
  5. building-soc-playbook-for-ransomware · mukul975 bundle
    Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees.
    24.6k
    repo stars
  6. conducting-phishing-incident-response · mukul975 bundle
    Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise, quarantining malicious messages, and remediating affected accounts.
    24.6k
    repo stars

Frequently asked questions

How do I install the investigating-phishing-email-incident skill?

Run npx skillmds add mukul975/investigating-phishing-email-incident in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the investigating-phishing-email-incident skill do?

Investigate phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. It is listed under Security, Data & Analytics, Docs & Writing, Incident Response, SQL & Databases on SkillMD.

Is investigating-phishing-email-incident safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with investigating-phishing-email-incident?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is investigating-phishing-email-incident free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published investigating-phishing-email-incident?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.