Agent skill

Performing Adversary In The Middle Phishing Detection

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure…

Apache-2.0Auto-check passedSecurity

Install Performing Adversary In The Middle Phishing Detection

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-adversary-in-the-middle-phishing-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-adversary-in-the-middle-phishing-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-adversary-in-the-middle-phishing-detection .claude/skills/performing-adversary-in-the-middle-phishing-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-adversary-in-the-middle-phishing-detection
GitHub stars
34k
Token cost
~1.7k tokens
SKILL.md length
655 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure…

  • Works in 5 steps: Deploy Phishing-Resistant MFA → Configure Conditional Access Policies → Build AiTM Detection Rules → …
  • Investigating suspected MFA-bypass phishing
  • SKILL.md covers Overview, When to Use, Prerequisites and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Performing Adversary In The Middle Phishing Detection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure AD/Entra sign-in logs, SIEM alerts, and EDR telemetry. Use when investigating suspected MFA-bypass phishing or session token theft, or building detection and response playbooks against reverse-proxy phishing kits.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Cloud networking and Security operations. It works with Microsoft Entra ID and Microsoft 365. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Investigating suspected MFA-bypass phishing
  • Session token theft
  • Building detection and response playbooks against reverse-proxy phishing kits

Example prompts

  • “/performing-adversary-in-the-middle-phishing-detection”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Deploy Phishing-Resistant MFA
  2. Configure Conditional Access Policies
  3. Build AiTM Detection Rules
  4. Monitor Web Proxy for AiTM Infrastructure
  5. Implement Post-Compromise Detection

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Adversary In The Middle Phishing Detection loads about 1.7k tokens when it runs, and up to ~3.2k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 655 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 655 words, ~1,665 tokens.

Download SKILL.mdSave it as .claude/skills/performing-adversary-in-the-middle-phishing-detection/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-adversary-in-the-middle-phishing-detection
description
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure AD/Entra sign-in logs, SIEM alerts, and EDR telemetry. Use when investigating suspected MFA-bypass phishing or session token theft, or building detection and response playbooks against reverse-proxy phishing kits.
domain
cybersecurity
subdomain
phishing-defense
tags
aitm, evilproxy, evilginx, phishing, mfa-bypass, session-hijacking, reverse-proxy, credential-theft
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AT-01, DE.CM-09, RS.CO-02, DE.AE-02
mitre_attack
T1566, T1598, T1534, T1036, T1003
mitre_f3.version
1.1
mitre_f3.tactics
initial-access, positioning

Performing Adversary-in-the-Middle Phishing Detection

Overview

Adversary-in-the-Middle (AiTM) phishing attacks use reverse-proxy infrastructure to sit between the victim and the legitimate authentication service, intercepting both credentials and session cookies in real time. This allows attackers to bypass multi-factor authentication (MFA). The most prevalent PhaaS kits in 2025 include Tycoon 2FA, Sneaky 2FA, EvilProxy, and Evilginx. Over 1 million PhaaS attacks were detected in January-February 2025 alone. These attacks have evolved from QR codes to HTML attachments and SVG files for link distribution.

When to Use

  • When conducting security assessments that involve performing adversary in the middle phishing detection
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Azure AD / Entra ID Conditional Access policies
  • SIEM with authentication log ingestion (Azure AD sign-in logs)
  • Web proxy with SSL inspection and URL categorization
  • Endpoint Detection and Response (EDR) solution
  • FIDO2/phishing-resistant MFA capability

Key Concepts

How AiTM Works
  1. Victim receives phishing email with link to attacker-controlled domain
  2. Attacker domain runs reverse proxy that mirrors legitimate login page
  3. Victim enters credentials on proxied page; credentials captured in transit
  4. Reverse proxy forwards credentials to real authentication service
  5. MFA challenge sent to victim; victim completes MFA on proxied page
  6. Attacker captures session cookie returned by legitimate service
  7. Attacker replays session cookie to access victim's account without MFA
Major AiTM Kits (2025)
KitTypePrimary TargetsEvasion
Tycoon 2FAPhaaSMicrosoft 365, GoogleCAPTCHA, Cloudflare turnstile
EvilProxyPhaaSMicrosoft 365, Google, OktaRandom URLs, IP rotation
EvilginxOpen-sourceAny web applicationCustom phishlets
Sneaky 2FAPhaaSMicrosoft 365Anti-bot checks
NakedPagesPhaaSMultipleMinimal infrastructure
Detection Indicators
  • Authentication from unusual IP not matching user profile
  • Session cookie reuse from different IP/device than authentication
  • Login page served from non-Microsoft/non-Google infrastructure
  • CDN requests to legitimate auth providers from phishing domains
  • Impossible travel between authentication and session usage

Workflow

Step 1: Deploy Phishing-Resistant MFA
  • Implement FIDO2 security keys or Windows Hello for Business for high-value accounts
  • Configure Conditional Access to require phishing-resistant MFA for admins
  • Enable certificate-based authentication where possible
  • Disable SMS and voice MFA for privileged accounts
  • AiTM cannot intercept FIDO2 because authentication is bound to origin domain
Show full SKILL.md (284 more words)Show less
Step 2: Configure Conditional Access Policies
  • Require compliant/managed device for sensitive application access
  • Block authentication from anonymous proxies and Tor exit nodes
  • Enforce token binding to limit session cookie replay
  • Configure continuous access evaluation (CAE) for real-time token revocation
  • Implement sign-in risk policies that require re-authentication for risky sign-ins
Step 3: Build AiTM Detection Rules
  • Alert on sign-in followed by session from different IP within 10 minutes
  • Detect authentication where proxy IP does not match user's expected location
  • Monitor for impossible travel patterns in session usage
  • Alert on inbox rules created immediately after authentication (common post-compromise)
  • Detect new MFA method registration from suspicious sign-in
Step 4: Monitor Web Proxy for AiTM Infrastructure
  • Log and analyze DNS queries to newly registered domains
  • Detect connections to known PhaaS infrastructure IPs
  • Alert on authentication page backgrounds loaded from legitimate CDNs through proxy domains
  • Monitor for SSL certificates issued to domains mimicking corporate login pages
  • Block access to known EvilProxy/Evilginx infrastructure via threat intelligence
Step 5: Implement Post-Compromise Detection
  • Alert on mailbox forwarding rules created after suspicious authentication
  • Detect OAuth app consent after AiTM sign-in
  • Monitor for email sending patterns indicating BEC follow-up
  • Alert on SharePoint/OneDrive mass download after session hijack
  • Track lateral movement from compromised account

Tools & Resources

  • Microsoft Entra ID Protection: Risk-based Conditional Access
  • Azure AD Sign-in Logs: Authentication event analysis
  • Okta ThreatInsight: AiTM proxy detection at IdP level
  • Sekoia TDR: AiTM campaign tracking and intelligence
  • Evilginx (defensive): Understanding attack mechanics for detection

Validation

  • Phishing-resistant MFA blocks AiTM session capture in test scenario
  • Conditional Access denies session replay from different device/IP
  • SIEM alerts fire on simulated AiTM sign-in patterns
  • Web proxy blocks connections to known PhaaS infrastructure
  • Post-compromise rules detect inbox rule creation after suspicious auth

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-adversary-in-the-middle-phishing-detection of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Adversary In The Middle Phishing Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Adversary In The Middle Phishing Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Adversary In The Middle Phishing Detection this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.0
Defender Xdrvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Sentinelvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Investigating M365 Entratrilwu/secskills157—~4.1kAutomated safety check: PassMIT
Dd Azure Integrationdatadog-labs/agent-skills177—~7.1kAutomated safety check: NotesMIT
Entra Agent Idmicrosoft/skills3.1k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Defender Xdr

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with…

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Sentinel

    vinayaklatthe/microsoft-security-skills

    Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Investigating M365 Entra

    trilwu/secskills

    Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule…

    157 GitHub stars~4.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Dd Azure Integration

    datadog-labs/agent-skills

    Set up the Datadog Azure integration with Terraform - creates an Entra ID app registration and service principal, assigns Monitoring Reader across the chosen subscriptions and management groups…

    177 GitHub stars~7.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Entra Agent Id

    microsoft/skills

    Official

    Microsoft Entra Agent ID (preview) for creating OAuth2-capable AI agent identities via Microsoft Graph beta API.

    3.1k GitHub stars~2.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Querying AWS Cloudwatch

    aws/agent-toolkit-for-aws

    Official

    Runs SQL queries on CloudWatch Logs data exported as Apache Iceberg tables in S3 Tables.

    2.8k GitHub stars~3.5k tokensUpdated yesterday
    DatabasesAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Performing Adversary In The Middle Phishing Detection

What does Performing Adversary In The Middle Phishing Detection do?

Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure…. Performing Adversary In The Middle Phishing Detection is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure AD/Entra sign-in logs, SIEM alerts, and EDR telemetry.

When should I use Performing Adversary In The Middle Phishing Detection?

Performing Adversary In The Middle Phishing Detection fits situations like: investigating suspected MFA-bypass phishing; session token theft; building detection and response playbooks against reverse-proxy phishing kits.

How do I install Performing Adversary In The Middle Phishing Detection in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-adversary-in-the-middle-phishing-detection -a claude-code`. Or copy the skill folder (skills/performing-adversary-in-the-middle-phishing-detection in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-adversary-in-the-middle-phishing-detection in your project. Claude Code loads it when a task matches its description.

How do I install Performing Adversary In The Middle Phishing Detection in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-adversary-in-the-middle-phishing-detection -a codex`. Or copy the skill folder (skills/performing-adversary-in-the-middle-phishing-detection in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-adversary-in-the-middle-phishing-detection in your project. Codex loads it when a task matches its description.

Can I use Performing Adversary In The Middle Phishing Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-adversary-in-the-middle-phishing-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-adversary-in-the-middle-phishing-detection, .gemini/skills/performing-adversary-in-the-middle-phishing-detection, .github/skills/performing-adversary-in-the-middle-phishing-detection and .opencode/skills/performing-adversary-in-the-middle-phishing-detection in your project.

What does Performing Adversary In The Middle Phishing Detection need to run?

Going by SKILL.md and its folder, Performing Adversary In The Middle Phishing Detection needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Performing Adversary In The Middle Phishing Detection access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Performing Adversary In The Middle Phishing Detection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Adversary In The Middle Phishing Detection use?

Performing Adversary In The Middle Phishing Detection is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Adversary In The Middle Phishing Detection use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Performing Adversary In The Middle Phishing Detection?

Skills that share tags, products or a category with Performing Adversary In The Middle Phishing Detection: Defender Xdr (vinayaklatthe/microsoft-security-skills, 175 stars), Sentinel (vinayaklatthe/microsoft-security-skills, 175 stars), Investigating M365 Entra (trilwu/secskills, 157 stars) and Dd Azure Integration (datadog-labs/agent-skills, 177 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Adversary In The Middle Phishing Detection?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.