investigating-m365-entra
Investigate a Microsoft 365 and Entra ID compromise where the only evidence is cloud logs — the Unified Audit Log, Entra sign-in and audit logs, OAuth app-consent grants, and mailbox inbox/forwarding rules — to reconstruct business email compromise, token and session theft, and consent abuse. Use for a suspected M365/Entra account takeover with no host or memory to image. Preserve the Unified Audit Log first; its retention is finite and the attacker's rules keep working while you look.
Informations de source
- Dépôt
- EvilFreelancer/secs
- Dernière activité de la source
- 8 août 2026 à 20:56
- Langue détectée de SKILL.md
- anglais
- Étoiles
- 9
- Forks
- 2
Options d'installation
Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.
Vérifiez les fichiers source
Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.