Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule…
Install the "investigating-m365-entra" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-m365-entra into .claude/skills/investigating-m365-entra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-m365-entra", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add trilwu/secskills --skill investigating-m365-entra -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "investigating-m365-entra" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-m365-entra into .agents/skills/investigating-m365-entra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-m365-entra", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add trilwu/secskills --skill investigating-m365-entra -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "investigating-m365-entra" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-m365-entra into .cursor/skills/investigating-m365-entra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-m365-entra", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add trilwu/secskills --skill investigating-m365-entra -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "investigating-m365-entra" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-m365-entra into .gemini/skills/investigating-m365-entra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-m365-entra", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add trilwu/secskills --skill investigating-m365-entra -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "investigating-m365-entra" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-m365-entra into .github/skills/investigating-m365-entra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-m365-entra", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add trilwu/secskills --skill investigating-m365-entra -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "investigating-m365-entra" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-m365-entra into .opencode/skills/investigating-m365-entra/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-m365-entra", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
investigating-m365-entra
GitHub stars
157
Token cost
~4.1k tokens
SKILL.md length
1,132 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT
At a glance
Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule…
Works in 4 steps: Anchor on the earliest suspicious sign-in → Pull sign-in, UAL, and audit events for… → Merge into a single UTC timeline → …
Responding to a BEC incident
SKILL.md covers When to Use, When NOT to Use, Log Landscape and Retention and Unified Audit Log (UAL), plus 9 more sections
Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
What it does
Investigating M365 Entra is an agent skill from trilwu/secskills. Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule manipulation, and contain compromised identities. Use when responding to a BEC incident, investigating Entra ID compromise, analyzing suspicious OAuth app permissions, tracing mail forwarding abuse, or reviewing Azure AD sign-in anomalies.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering OAuth and OpenID Connect, Cloud office suites and Security operations. It works with Microsoft Entra ID and Microsoft 365. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
When your agent uses it
Responding to a BEC incident
Investigating Entra ID compromise
Analyzing suspicious OAuth app permissions
Tracing mail forwarding abuse
Example prompts
“/investigating-m365-entra”
Requirements
Python 3
Workflow steps
4 steps, taken from the first numbered list in SKILL.md.
1Anchor on the earliest suspicious sign-in
2Pull sign-in, UAL, and audit events for that user +/- 7 days
3Merge into a single UTC timeline
4Look for the pattern: sign-in, reconnaissance, persistence (rule/forwarding/OAuth), action on objectives
What it can do on your machine
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are powershell and kusto).
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Investigating M365 Entra loads about 4.1k tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 1,132 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~116
When it runs· the whole SKILL.md, loaded when a task matches
~4.1k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/investigating-m365-entra/SKILL.md (or your agent's skills folder).
name
investigating-m365-entra
description
Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule manipulation, and contain compromised identities. Use when responding to a BEC incident, investigating Entra ID compromise, analyzing suspicious OAuth app permissions, tracing mail forwarding abuse, or reviewing Azure AD sign-in anomalies.
verified
2026-07-27
Investigating M365 and Entra ID
M365/Entra investigations differ from on-premises DFIR -- there are no disk
images, no memory dumps, and no event logs you can collect yourself. Everything
comes from API queries against Microsoft's log stores, several of which require
E5 licensing or advanced audit to retain what you need. Knowing which logs
exist, which ones are missing, and how long they last is half the investigation.
When to Use
Business email compromise (BEC) -- unauthorized mailbox access, forwarding, or impersonation
Role assignments, app registrations, credential changes
Identity Protection
30d
Requires P2
Risky sign-ins, risk detections
Defender for Cloud Apps
180d
Requires MDCA license
Activity log, OAuth app inventory
Mailbox audit log
90d (on by default)
MailItemsAccessed requires E5
Mail access, send-as, delegate ops
Get the retention right before you conclude anything from a gap. Since
17 October 2023 the Audit (Standard) default is 180 days, not the 90 days
most older material still cites — records generated before that date kept the
old 90-day window. One year is the default only for users holding an E5 (or
Purview Audit add-on) licence, and even then only for Exchange, SharePoint,
OneDrive, and Entra ID. An E3 tenant therefore has 180 days of UAL and no
MailItemsAccessed, and cannot extend retention in-product.
Retention is per-user by licence, not per-tenant: in a mixed tenant the same
query can return a year of history for an E5 custodian and 180 days for the E3
account next to them. Confirm the licence on the account you are investigating
before you read an empty result as "no activity".
State that gap explicitly. Check SIEM or Log Analytics for extended retention.
Unified Audit Log (UAL)
The UAL is the single richest data source. Every investigation starts here.
Red flags: rules targeting keywords ("security", "password", "MFA"), rules
deleting or moving to RSS Feeds / Conversation History, blank-named rules,
forwarding to free email providers, rules created after the first suspicious
sign-in.
eDiscovery and Content Search
powershell
Connect-IPPSSession -UserPrincipalName admin@tenant.onmicrosoft.com
# Preserve mailbox content -- do this early
Set-Mailbox -Identity compromised@contoso.com -LitigationHoldEnabled $true
# Search outbound mail from compromised account
New-ComplianceSearch -Name "IR-2026-042 Outbound" `
-ExchangeLocation compromised@contoso.com `
-ContentMatchQuery "sent>=2026-07-01 AND sent<=2026-07-20"
Start-ComplianceSearch -Identity "IR-2026-042 Outbound"
Place litigation holds before retention policies or the attacker can purge evidence.
Azure AD Audit Log Analysis
kusto
// Role assignments
AuditLogs
| where OperationName == "Add member to role"
| extend TargetUser = tostring(TargetResources[0].userPrincipalName),
RoleName = tostring(TargetResources[0].modifiedProperties[1].newValue)
| project TimeGenerated, InitiatedBy, TargetUser, RoleName
// Service principal credential changes (persistence)
AuditLogs
| where OperationName in ("Add service principal credentials",
"Update application - Certificates and secrets management")
| project TimeGenerated, InitiatedBy, TargetResources
// Conditional Access policy changes
AuditLogs
| where OperationName has "conditional access"
| project TimeGenerated, OperationName, InitiatedBy, Result
// MFA method changes (attacker registering their own factor)
AuditLogs
| where OperationName in ("User registered security info",
"Admin registered security info", "User deleted security info")
| project TimeGenerated, OperationName, InitiatedBy, TargetResources
Attackers with Application Admin or Global Admin can add credentials to
existing app registrations for persistent, MFA-independent access:
Session revocation alone is insufficient -- tokens may remain valid up to one
hour. Disable the account for immediate lockout. After containment, verify: no
forwarding remains, no unknown delegates, no unknown OAuth grants, no
attacker-registered MFA methods, no service principal credentials from the
compromise window.
Rationalizations to Reject
"We reset the password, so the account is secure." Refresh tokens, OAuth
grants, inbox rules, forwarding, and delegate access all survive a password
reset. Revoke sessions and audit every persistence mechanism.
"We only have E3, so we cannot investigate mail access." MailItemsAccessed
is unavailable, but sign-in logs, UAL operations, inbox rules, and forwarding
still exist. State the gap and work with what you have.
"The sign-in was from a VPN, so it is probably the user." Correlate the
exit IP, user agent, and timing against established patterns. Attackers use
VPNs too.
"No alerts fired in Defender, so there is no compromise." Defender requires
the right license tier and policy config. Absence of alerts is not evidence
of absence.
"The OAuth app only has delegated permissions." Delegated permissions with
a valid refresh token give persistent access without needing the password again.
"We blocked the IP, so the attacker is locked out." Attackers rotate IPs.
Revoke the tokens and credentials, not just the network path.
"Logs only go back 30 days, so the compromise started within that window."
That is your visibility limit, not the attacker's timeline. Document the
limitation and check SIEM for extended retention.
References
responding-to-incidents -- broader IR methodology and evidence handling
attacking-entra-id -- offensive Entra ID techniques, useful for understanding attacker methods
Investigating M365 Entra next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Investigating M365 Entra compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Investigating M365 Entra this skilltrilwu/secskills
Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…
Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with…
Configures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication…
Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule…. Investigating M365 Entra is an agent skill from trilwu/secskills. Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule manipulation, and contain compromised identities.
When should I use Investigating M365 Entra?
Investigating M365 Entra fits situations like: responding to a BEC incident; investigating Entra ID compromise; analyzing suspicious OAuth app permissions; tracing mail forwarding abuse.
How do I install Investigating M365 Entra in Claude Code?
Run `npx skills add trilwu/secskills --skill investigating-m365-entra -a claude-code`. Or copy the skill folder (secskills-defense/skills/investigating-m365-entra in trilwu/secskills) into .claude/skills/investigating-m365-entra in your project. Claude Code loads it when a task matches its description.
How do I install Investigating M365 Entra in Codex?
Run `npx skills add trilwu/secskills --skill investigating-m365-entra -a codex`. Or copy the skill folder (secskills-defense/skills/investigating-m365-entra in trilwu/secskills) into .agents/skills/investigating-m365-entra in your project. Codex loads it when a task matches its description.
Can I use Investigating M365 Entra in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill investigating-m365-entra -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigating-m365-entra, .gemini/skills/investigating-m365-entra, .github/skills/investigating-m365-entra and .opencode/skills/investigating-m365-entra in your project.
What does Investigating M365 Entra need to run?
SKILL.md names no scripts, command-line tools or credentials: Investigating M365 Entra is instructions for the agent only. Our summary lists: Python 3.
Does Investigating M365 Entra access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Investigating M365 Entra safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Investigating M365 Entra use?
Investigating M365 Entra is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Investigating M365 Entra use?
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Investigating M365 Entra?
Skills that share tags, products or a category with Investigating M365 Entra: Detecting Email Account Compromise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Defender Xdr (vinayaklatthe/microsoft-security-skills, 175 stars), Implementing Google Workspace Sso Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Zero Trust For SaaS Applications (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Investigating M365 Entra?
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.