Agent skill

Investigating M365 Entra

by trilwu in trilwu/secskills

Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule…

MITAuto-check passedBackend & APIs

Install Investigating M365 Entra

skills CLI
$ npx skills add trilwu/secskills --skill investigating-m365-entra -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills investigating-m365-entra --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/investigating-m365-entra .claude/skills/investigating-m365-entra && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
investigating-m365-entra
GitHub stars
157
Token cost
~4.1k tokens
SKILL.md length
1,132 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule…

  • Works in 4 steps: Anchor on the earliest suspicious sign-in → Pull sign-in, UAL, and audit events for… → Merge into a single UTC timeline → …
  • Responding to a BEC incident
  • SKILL.md covers When to Use, When NOT to Use, Log Landscape and Retention and Unified Audit Log (UAL), plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Investigating M365 Entra is an agent skill from trilwu/secskills. Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule manipulation, and contain compromised identities. Use when responding to a BEC incident, investigating Entra ID compromise, analyzing suspicious OAuth app permissions, tracing mail forwarding abuse, or reviewing Azure AD sign-in anomalies.

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering OAuth and OpenID Connect, Cloud office suites and Security operations. It works with Microsoft Entra ID and Microsoft 365. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Responding to a BEC incident
  • Investigating Entra ID compromise
  • Analyzing suspicious OAuth app permissions
  • Tracing mail forwarding abuse

Example prompts

  • “/investigating-m365-entra”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Anchor on the earliest suspicious sign-in
  2. Pull sign-in, UAL, and audit events for that user +/- 7 days
  3. Merge into a single UTC timeline
  4. Look for the pattern: sign-in, reconnaissance, persistence (rule/forwarding/OAuth), action on objectives

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are powershell and kusto).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Investigating M365 Entra loads about 4.1k tokens when it runs. Until then it costs about 116 tokens; SKILL.md has 1,132 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,132 words, ~4,082 tokens.

Download SKILL.mdSave it as .claude/skills/investigating-m365-entra/SKILL.md (or your agent's skills folder).
name
investigating-m365-entra
description
Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule manipulation, and contain compromised identities. Use when responding to a BEC incident, investigating Entra ID compromise, analyzing suspicious OAuth app permissions, tracing mail forwarding abuse, or reviewing Azure AD sign-in anomalies.
verified
2026-07-27

Investigating M365 and Entra ID

M365/Entra investigations differ from on-premises DFIR -- there are no disk images, no memory dumps, and no event logs you can collect yourself. Everything comes from API queries against Microsoft's log stores, several of which require E5 licensing or advanced audit to retain what you need. Knowing which logs exist, which ones are missing, and how long they last is half the investigation.

When to Use

  • Business email compromise (BEC) -- unauthorized mailbox access, forwarding, or impersonation
  • Entra ID account compromise -- suspicious sign-ins, token replay, credential stuffing
  • Suspicious OAuth consent grants -- third-party apps with excessive permissions
  • Mailbox rule manipulation -- inbox rules hiding attacker communications or forwarding mail
  • Azure AD sign-in anomalies -- impossible travel, legacy auth, anonymizer networks
  • Conditional Access or MFA tampering -- policy changes, MFA fatigue attacks

When NOT to Use

  • Broader incident response methodology -- use responding-to-incidents
  • Offensive testing of Entra ID -- use attacking-entra-id
  • An Azure resource/subscription compromise -- use investigating-azure-incidents
  • An AWS compromise -- use investigating-aws-incidents
  • Other cloud infrastructure (GCP, offensive testing) -- use exploiting-cloud-platforms
  • Building detection rules from findings -- use engineering-detections

Log Landscape and Retention

Before you query anything, establish what you have and how far back it goes. Missing logs are a finding, not a reason to skip the question.

Log sourceRetention (default)License gateKey operations
Unified Audit Log (UAL)180d default; 1 year for E5-licensed usersMailItemsAccessed requires E5MailItemsAccessed, New-InboxRule, Set-Mailbox, consent grants
Entra ID sign-in logs30dExport to Log Analytics for longerSign-in events, CA evaluation, MFA results
Entra ID audit logs30dNoneRole assignments, app registrations, credential changes
Identity Protection30dRequires P2Risky sign-ins, risk detections
Defender for Cloud Apps180dRequires MDCA licenseActivity log, OAuth app inventory
Mailbox audit log90d (on by default)MailItemsAccessed requires E5Mail access, send-as, delegate ops

Get the retention right before you conclude anything from a gap. Since 17 October 2023 the Audit (Standard) default is 180 days, not the 90 days most older material still cites — records generated before that date kept the old 90-day window. One year is the default only for users holding an E5 (or Purview Audit add-on) licence, and even then only for Exchange, SharePoint, OneDrive, and Entra ID. An E3 tenant therefore has 180 days of UAL and no MailItemsAccessed, and cannot extend retention in-product.

Retention is per-user by licence, not per-tenant: in a mixed tenant the same query can return a year of history for an E5 custodian and 180 days for the E3 account next to them. Confirm the licence on the account you are investigating before you read an empty result as "no activity". State that gap explicitly. Check SIEM or Log Analytics for extended retention.

Unified Audit Log (UAL)

The UAL is the single richest data source. Every investigation starts here.

powershell
Connect-ExchangeOnline -UserPrincipalName admin@tenant.onmicrosoft.com

# Basic search -- always constrain by date and user
Search-UnifiedAuditLog -StartDate "2026-07-01" -EndDate "2026-07-20" `
  -UserIds compromised@contoso.com -ResultSize 5000

# Search specific operations
Search-UnifiedAuditLog -StartDate "2026-07-01" -EndDate "2026-07-20" `
  -Operations "New-InboxRule","Set-InboxRule","Set-Mailbox","Add-MailboxPermission" `
  -ResultSize 5000

# MailItemsAccessed (E5 only)
Search-UnifiedAuditLog -StartDate "2026-07-01" -EndDate "2026-07-20" `
  -Operations MailItemsAccessed -UserIds compromised@contoso.com -ResultSize 5000

# Export -- AuditData field is JSON, expand it
Search-UnifiedAuditLog -StartDate "2026-07-01" -EndDate "2026-07-20" `
  -UserIds compromised@contoso.com -ResultSize 5000 |
  Select-Object CreationDate, UserIds, Operations,
    @{N='AuditData';E={$_.AuditData | ConvertFrom-Json | ConvertTo-Json -Depth 10}} |
  Export-Csv -Path .\ual_export.csv -NoTypeInformation
Key UAL operations
OperationSignificance
MailItemsAccessedBind = single item read, Sync = bulk download. Bulk sync is the BEC exfiltration indicator.
New-InboxRule / Set-InboxRuleRules hiding replies or forwarding. Check for keyword targets: "invoice", "payment", "security".
Set-MailboxForwardingSMTPAddress or ForwardingAddress changed -- silent external forwarding.
Add-MailboxPermissionFullAccess or SendAs delegation -- persistence.
Consent to applicationOAuth grant. AuditData contains the permissions.
Add service principal credentialsNew secret/certificate on an app registration.
HardDelete / SoftDeleteEvidence destruction -- attacker deleting sent items.

The UAL caps at 50,000 results per query. Narrow the date range if you hit it.

Entra ID Sign-In Analysis

Query sign-in logs and look for:

  • Impossible travel -- distant locations within an impossible timeframe
  • Anonymous IPs -- Tor exits, VPN services, known anonymizers
  • Legacy auth -- IMAP, POP3, SMTP AUTH bypass MFA unless CA blocks them
  • Token replay -- same correlation ID from different source IPs
  • Anomalous user agents -- Python requests, PowerShell hitting OWA or Graph
kusto
// Sign-ins from the compromised account
SigninLogs
| where UserPrincipalName == "compromised@contoso.com"
| where TimeGenerated > ago(30d)
| project TimeGenerated, AppDisplayName, IPAddress, Location,
    ClientAppUsed, ResultType, AuthenticationRequirement, MfaDetail, RiskState
| order by TimeGenerated asc

// Legacy auth sign-ins that bypass MFA
SigninLogs
| where ClientAppUsed in ("IMAP4", "POP3", "SMTP", "Exchange ActiveSync",
    "MAPI Over HTTP", "Outlook Anywhere", "Exchange Web Services")
| where ResultType == 0
| summarize count() by UserPrincipalName, ClientAppUsed, IPAddress
MFA analysis
  • ResultType 50074 -- MFA required, not completed
  • ResultType 50076 -- MFA completed (attacker had the factor or used MFA fatigue)
  • AuthenticationRequirement = singleFactorAuthentication -- MFA not required (CA gap)
  • Check MfaDetail -- push acceptance after repeated prompts = MFA fatigue

Illicit consent grants are the most-missed persistence in M365 compromise.

powershell
Connect-MgGraph -Scopes "Application.Read.All","Directory.Read.All"

# Delegated permission grants -- look for Mail.Read, Files.ReadWrite, etc.
Get-MgOauth2PermissionGrant -All | Where-Object {
    $_.Scope -match "Mail.Read|Mail.ReadWrite|Files.ReadWrite|User.Read.All"
} | Format-Table ClientId, ConsentType, Scope, PrincipalId

# Application permission assignments
Get-MgServicePrincipal -All | ForEach-Object {
    $sp = $_
    Get-MgServicePrincipalAppRoleAssignment -ServicePrincipalId $sp.Id -ErrorAction SilentlyContinue |
    Select-Object @{N='AppName';E={$sp.DisplayName}}, @{N='AppId';E={$sp.AppId}},
                  PrincipalDisplayName, @{N='Created';E={$_.CreatedDateTime}}
}
PermissionRisk
Mail.Read / Mail.ReadWriteEmail exfiltration. Suspicious on unknown apps.
Files.ReadWrite.AllFull SharePoint/OneDrive access.
Directory.ReadWrite.AllCan modify users, groups, roles.
full_access_as_appExchange app-level mailbox access -- almost never legitimate for third parties.

Distinguish delegated consent (one user's data) from admin consent (tenant-wide). Admin consent to a malicious app exposes every user.

Show full SKILL.md (422 more words)Show less

Mailbox Rule Forensics

Inbox rules persist after password resets. Always check them.

powershell
# Inbox rules
Get-InboxRule -Mailbox compromised@contoso.com |
  Select-Object Name, Enabled, MoveToFolder, DeleteMessage, ForwardTo,
    RedirectTo, MarkAsRead | Format-List

# Mailbox-level forwarding
Get-Mailbox -Identity compromised@contoso.com |
  Select-Object ForwardingSMTPAddress, ForwardingAddress, DeliverToMailboxAndForward

# All mailboxes with external forwarding
Get-Mailbox -ResultSize Unlimited |
  Where-Object { $_.ForwardingSMTPAddress -ne $null } |
  Select-Object UserPrincipalName, ForwardingSMTPAddress

# Transport rules
Get-TransportRule | Where-Object { $_.RedirectMessageTo -or $_.BlindCopyTo } |
  Select-Object Name, State, RedirectMessageTo, BlindCopyTo

# Delegate access
Get-MailboxPermission -Identity compromised@contoso.com |
  Where-Object { $_.User -ne "NT AUTHORITY\SELF" -and -not $_.IsInherited }

Red flags: rules targeting keywords ("security", "password", "MFA"), rules deleting or moving to RSS Feeds / Conversation History, blank-named rules, forwarding to free email providers, rules created after the first suspicious sign-in.

powershell
Connect-IPPSSession -UserPrincipalName admin@tenant.onmicrosoft.com

# Preserve mailbox content -- do this early
Set-Mailbox -Identity compromised@contoso.com -LitigationHoldEnabled $true

# Search outbound mail from compromised account
New-ComplianceSearch -Name "IR-2026-042 Outbound" `
  -ExchangeLocation compromised@contoso.com `
  -ContentMatchQuery "sent>=2026-07-01 AND sent<=2026-07-20"
Start-ComplianceSearch -Identity "IR-2026-042 Outbound"

Place litigation holds before retention policies or the attacker can purge evidence.

Azure AD Audit Log Analysis

kusto
// Role assignments
AuditLogs
| where OperationName == "Add member to role"
| extend TargetUser = tostring(TargetResources[0].userPrincipalName),
         RoleName = tostring(TargetResources[0].modifiedProperties[1].newValue)
| project TimeGenerated, InitiatedBy, TargetUser, RoleName

// Service principal credential changes (persistence)
AuditLogs
| where OperationName in ("Add service principal credentials",
    "Update application - Certificates and secrets management")
| project TimeGenerated, InitiatedBy, TargetResources

// Conditional Access policy changes
AuditLogs
| where OperationName has "conditional access"
| project TimeGenerated, OperationName, InitiatedBy, Result

// MFA method changes (attacker registering their own factor)
AuditLogs
| where OperationName in ("User registered security info",
    "Admin registered security info", "User deleted security info")
| project TimeGenerated, OperationName, InitiatedBy, TargetResources

Attackers with Application Admin or Global Admin can add credentials to existing app registrations for persistent, MFA-independent access:

powershell
Get-MgApplication -All | ForEach-Object {
    $app = $_
    $app.PasswordCredentials + $app.KeyCredentials | Where-Object {
        $_.StartDateTime -gt (Get-Date).AddDays(-30)
    } | Select-Object @{N='App';E={$app.DisplayName}}, @{N='AppId';E={$app.AppId}},
                      StartDateTime, EndDateTime
}

Timeline Construction

Correlate across the three primary log sources:

Sign-in logs  -->  When and where the attacker authenticated
Audit logs    -->  Configuration changes they made
UAL           -->  Data they accessed or modified
  1. Anchor on the earliest suspicious sign-in
  2. Pull sign-in, UAL, and audit events for that user +/- 7 days
  3. Merge into a single UTC timeline
  4. Look for the pattern: sign-in, reconnaissance, persistence (rule/forwarding/OAuth), action on objectives
UTC Timestamp        | Source  | Event                                    | Detail
2026-07-12 08:41:22  | SignIn  | Sign-in from 198.51.x.x                  | Nigeria, no MFA
2026-07-12 08:42:05  | UAL     | MailItemsAccessed (Sync)                 | 847 items via Graph
2026-07-12 08:43:18  | UAL     | New-InboxRule "."                        | Delete "security alert"
2026-07-12 08:44:01  | UAL     | Set-Mailbox                              | ForwardingSMTPAddress set
2026-07-12 08:45:33  | UAL     | Consent to application                   | Mail.Read, Mail.Send
2026-07-12 09:12:44  | UAL     | Send (SendAs)                            | Invoice redirect to vendor

Containment

Execute simultaneously once scoping is complete. Partial containment alerts the attacker.

powershell
# Revoke sessions and reset credentials
Revoke-MgUserSignInSession -UserId compromised@contoso.com
Update-MgUser -UserId compromised@contoso.com -PasswordProfile @{
    Password = (New-Guid).Guid + "!Aa1"; ForceChangePasswordNextSignIn = $true }

# Disable account if active compromise is ongoing
Update-MgUser -UserId compromised@contoso.com -AccountEnabled:$false

# Remove attacker inbox rules
Get-InboxRule -Mailbox compromised@contoso.com |
  Where-Object { $_.Name -match "^\.$|^$" -or $_.DeleteMessage -eq $true } |
  Remove-InboxRule -Confirm:$false

# Remove forwarding
Set-Mailbox -Identity compromised@contoso.com `
  -ForwardingSMTPAddress $null -ForwardingAddress $null `
  -DeliverToMailboxAndForward $false

# Remove unauthorized delegate access
Get-MailboxPermission -Identity compromised@contoso.com |
  Where-Object { $_.User -ne "NT AUTHORITY\SELF" -and -not $_.IsInherited } |
  ForEach-Object { Remove-MailboxPermission -Identity compromised@contoso.com `
    -User $_.User -AccessRights $_.AccessRights -Confirm:$false }

# Block malicious OAuth app
$sp = Get-MgServicePrincipal -Filter "appId eq '<malicious-app-id>'"
Update-MgServicePrincipal -ServicePrincipalId $sp.Id -AccountEnabled:$false
Get-MgOauth2PermissionGrant -Filter "clientId eq '$($sp.Id)'" |
  Remove-MgOauth2PermissionGrant

Session revocation alone is insufficient -- tokens may remain valid up to one hour. Disable the account for immediate lockout. After containment, verify: no forwarding remains, no unknown delegates, no unknown OAuth grants, no attacker-registered MFA methods, no service principal credentials from the compromise window.

Rationalizations to Reject

  • "We reset the password, so the account is secure." Refresh tokens, OAuth grants, inbox rules, forwarding, and delegate access all survive a password reset. Revoke sessions and audit every persistence mechanism.
  • "We only have E3, so we cannot investigate mail access." MailItemsAccessed is unavailable, but sign-in logs, UAL operations, inbox rules, and forwarding still exist. State the gap and work with what you have.
  • "The sign-in was from a VPN, so it is probably the user." Correlate the exit IP, user agent, and timing against established patterns. Attackers use VPNs too.
  • "No alerts fired in Defender, so there is no compromise." Defender requires the right license tier and policy config. Absence of alerts is not evidence of absence.
  • "The OAuth app only has delegated permissions." Delegated permissions with a valid refresh token give persistent access without needing the password again.
  • "We blocked the IP, so the attacker is locked out." Attackers rotate IPs. Revoke the tokens and credentials, not just the network path.
  • "Logs only go back 30 days, so the compromise started within that window." That is your visibility limit, not the attacker's timeline. Document the limitation and check SIEM for extended retention.

References

  • responding-to-incidents -- broader IR methodology and evidence handling
  • attacking-entra-id -- offensive Entra ID techniques, useful for understanding attacker methods
  • exploiting-cloud-platforms -- cloud infrastructure attacks beyond M365
  • engineering-detections -- building detection rules from investigation findings
  • hunting-threats -- proactive hunting in M365 and Entra ID telemetry

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-defense/skills/investigating-m365-entra of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Investigating M365 Entra next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Investigating M365 Entra compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Investigating M365 Entra this skilltrilwu/secskills157—~4.1kAutomated safety check: PassMIT
Detecting Email Account Compromisemukul975/Anthropic-Cybersecurity-Skills34k—~823Automated safety check: PassApache-2.0
Defender Xdrvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Implementing Google Workspace Sso Configurationmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Implementing Zero Trust For SaaS Applicationsmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
API GatewayCraftOS-dev/CraftBot3923 repos~7.1kAutomated safety check: PassMIT

Similar skills

  • Detecting Email Account Compromise

    mukul975/Anthropic-Cybersecurity-Skills

    Detect compromised O365 and Google Workspace email accounts by analyzing Unified Audit Logs and Azure AD sign-in logs for impossible travel, inbox rule creation/deletion (Set-InboxRule…

    34k GitHub stars~823 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Defender Xdr

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with…

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Implementing Google Workspace Sso Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Configures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Implementing Zero Trust For SaaS Applications

    mukul975/Anthropic-Cybersecurity-Skills

    Secures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • API Gateway

    CraftOS-dev/CraftBot

    Connect to 100+ APIs (Google Workspace, Microsoft 365, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth.

    392 GitHub starsUsed in 3 repos~7.1k tokens
    Backend & APIsAuto-check passed
  • Analyzing Office365 Audit Logs For Compromise

    mukul975/Anthropic-Cybersecurity-Skills

    Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.

    34k GitHub stars~584 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Investigating M365 Entra

What does Investigating M365 Entra do?

Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule…. Investigating M365 Entra is an agent skill from trilwu/secskills. Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule manipulation, and contain compromised identities.

When should I use Investigating M365 Entra?

Investigating M365 Entra fits situations like: responding to a BEC incident; investigating Entra ID compromise; analyzing suspicious OAuth app permissions; tracing mail forwarding abuse.

How do I install Investigating M365 Entra in Claude Code?

Run `npx skills add trilwu/secskills --skill investigating-m365-entra -a claude-code`. Or copy the skill folder (secskills-defense/skills/investigating-m365-entra in trilwu/secskills) into .claude/skills/investigating-m365-entra in your project. Claude Code loads it when a task matches its description.

How do I install Investigating M365 Entra in Codex?

Run `npx skills add trilwu/secskills --skill investigating-m365-entra -a codex`. Or copy the skill folder (secskills-defense/skills/investigating-m365-entra in trilwu/secskills) into .agents/skills/investigating-m365-entra in your project. Codex loads it when a task matches its description.

Can I use Investigating M365 Entra in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill investigating-m365-entra -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigating-m365-entra, .gemini/skills/investigating-m365-entra, .github/skills/investigating-m365-entra and .opencode/skills/investigating-m365-entra in your project.

What does Investigating M365 Entra need to run?

SKILL.md names no scripts, command-line tools or credentials: Investigating M365 Entra is instructions for the agent only. Our summary lists: Python 3.

Does Investigating M365 Entra access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Investigating M365 Entra safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Investigating M365 Entra use?

Investigating M365 Entra is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Investigating M365 Entra use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Investigating M365 Entra?

Skills that share tags, products or a category with Investigating M365 Entra: Detecting Email Account Compromise (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Defender Xdr (vinayaklatthe/microsoft-security-skills, 175 stars), Implementing Google Workspace Sso Configuration (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Zero Trust For SaaS Applications (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Investigating M365 Entra?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.