Skip to main content

investigating-m365-entra

Investigate a Microsoft 365 and Entra ID compromise where the only evidence is cloud logs — the Unified Audit Log, Entra sign-in and audit logs, OAuth app-consent grants, and mailbox inbox/forwarding rules — to reconstruct business email compromise, token and session theft, and consent abuse. Use for a suspected M365/Entra account takeover with no host or memory to image. Preserve the Unified Audit Log first; its retention is finite and the attacker's rules keep working while you look.

Zur Installation springen

Quellinformationen

Repository
EvilFreelancer/secs
Letzte Quellaktivität
8. August 2026 um 20:56
Erkannte Sprache von SKILL.md
Englisch
Sterne
9
Forks
2

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.