Agent skill

Compromise Recovery

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to…

MITAuto-check passedDevOps & Cloud

Install Compromise Recovery

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill compromise-recovery -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills compromise-recovery --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/compromise-recovery .claude/skills/compromise-recovery && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compromise-recovery
GitHub stars
175
Token cost
~2.4k tokens
SKILL.md length
1,078 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to…

  • Works in 8 steps: Engage qualified incident responders… → Establish a trusted foundation - Stand… → Preserve forensic evidence before… → …
  • Routine SOC investigation (use defender-xdr / sentinel)
  • SKILL.md covers When to use, Decide what stage you are at, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Compromise Recovery is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to prevent reentry. Covers trusted foundation (PAW), containment, eviction, identity recovery (krbtgt, federation), and post-eviction hardening. WHEN: compromise recovery, incident response, regain control after breach, evict attacker, tenant compromise, rebuild trust, ransomware recovery, post-breach hardening, kick out…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Incident response. It works with Microsoft Defender and Microsoft Entra ID. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Routine SOC investigation (use defender-xdr / sentinel)
  • For preventive hardening with no active compromise (use security-architecture / entra-id)

Example prompts

  • “/compromise-recovery”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Engage qualified incident responders immediately - For major incidents, engage Microsoft
  2. Establish a trusted foundation - Stand up out-of-band communications (separate Teams
  3. Preserve forensic evidence before remediating - Snapshot affected systems, export sign-
  4. Contain without tipping off - Limit the adversary's ability to act: protect crown
  5. Evict in a single coordinated action - Plan a sequenced removal across all known
  6. Reset identity trust - Reset the krbtgt account (twice, with sufficient interval
  7. Harden to prevent reentry - Enforce phishing-resistant MFA on all privileged and
  8. Transition to BAU - Hand off to a sustained security operations and improvement

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compromise Recovery loads about 2.4k tokens when it runs. Until then it costs about 220 tokens; SKILL.md has 1,078 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~220
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 1,078 words, ~2,390 tokens.

Download SKILL.mdSave it as .claude/skills/compromise-recovery/SKILL.md (or your agent's skills folder).
name
compromise-recovery
description
Guidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to prevent reentry. Covers trusted foundation (PAW), containment, eviction, identity recovery (krbtgt, federation), and post-eviction hardening. WHEN: compromise recovery, incident response, regain control after breach, evict attacker, tenant compromise, rebuild trust, ransomware recovery, post-breach hardening, kick out adversary, emergency response, attacker is in our tenant right now, ransomware hit our organisation, regain admin access after a breach, adversary has domain admin or Global Admin. DO NOT USE for routine SOC investigation (use defender-xdr / sentinel) or for preventive hardening with no active compromise (use security-architecture / entra-id).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Compromise Recovery

Compromise recovery is the disciplined process of regaining administrative control of an environment during or after a significant breach, evicting the adversary in a single coordinated action, and re-establishing a trustworthy security posture so the attacker cannot return.

When to use

Responding to a confirmed widespread compromise - tenant-wide Entra/AD compromise, ransomware, persistent adversary with Global Admin or Domain Admin - where normal remediation is insufficient and the existing infrastructure cannot be trusted.

Do not use this skill for:

  • Routine alert triage or single-host malware (use defender-xdr)
  • Pre-incident architecture hardening (use security-architecture, entra-id, paw-design)
  • Sentinel hunting and detection engineering (use sentinel)

Decide what stage you are at

SituationStageFirst action
Anomalies detected, not yet confirmed scopeInvestigateHunt + preserve evidence, do not tip off
Adversary confirmed, scope still expandingContainStand up trusted foundation (PAW), protect crown jewels
Adversary scope known, ready to removeEvictSingle coordinated action across all persistence
Adversary removed, validating no re-entryRecoverReset krbtgt, federation secrets, privileged creds
Stable, hardening to prevent recurrenceHardenMFA-everywhere, PIM, PAW, monitoring expansion
Hardening complete, back to BAUTransitionHand off to sustained SecOps + improvement

Rule of thumb: Never start eviction from the compromised environment. Stand up a trusted foundation first - dedicated admin workstations (PAW), out-of-band communications, a clean Entra tenant or cleanly-rebuilt admin accounts. Acting from untrusted infrastructure hands the adversary your response plan in real time.

Approach

  1. Engage qualified incident responders immediately - For major incidents, engage Microsoft Incident Response or a qualified DFIR partner. The cost of delay (re-entry, ransomware double-extortion, regulator timelines) dwarfs the engagement cost. Verify: an IR partner is engaged within the first 24 hours of confirmed compromise.
  2. Establish a trusted foundation - Stand up out-of-band communications (separate Teams tenant, signal/voice), secure admin devices (PAWs), and a clean admin identity path. Assume existing infrastructure - mail, chat, jump hosts, admin accounts - may be untrusted or monitored by the adversary. Verify: incident bridge is on out-of-band channel; responders authenticate from PAW or equivalent isolated workstation; no compromised admin account is used.
  3. Preserve forensic evidence before remediating - Snapshot affected systems, export sign- in logs, audit logs, mail items, and Entra/AD changes. Once you remediate you lose evidence; regulators and insurers will ask for it. Verify: forensic acquisitions are stored on isolated, write-protected media with chain of custody documented.
  4. Contain without tipping off - Limit the adversary's ability to act: protect crown jewels (privileged accounts, federation/signing keys, backup credentials), tighten Conditional Access in stealth mode where possible, monitor known adversary accounts without blocking them yet. Partial eviction warns the adversary and invites re-entrenchment under a new identity. Verify: containment actions are recorded in a sequenced runbook, not ad-hoc; nothing visible to the adversary has changed unless deliberate.
  5. Evict in a single coordinated action - Plan a sequenced removal across all known persistence: compromised accounts (disable + reset), app registrations and consent grants (review and revoke), mailbox rules and forwarding (delete), scheduled tasks / startup items, golden/forged Kerberos tickets, federation/SAML tokens, any added admin roles. Aim for one decisive action window rather than piecemeal changes. Verify: an eviction runbook lists every persistence artefact with owner, time, and verification step; rehearsed before execution.
  6. Reset identity trust - Reset the krbtgt account (twice, with sufficient interval for replication), reset all privileged credentials, rotate federation/SAML signing certificates, rotate Entra Connect sync account, and reset any service principal secrets the adversary could have touched. Verify: krbtgt reset is logged twice; federation cert rollover is complete; sign-in logs show no remaining sessions from compromised tokens.
  7. Harden to prevent reentry - Enforce phishing-resistant MFA on all privileged and high-risk users, move privileged roles into PIM with just-in-time activation and approvals, deploy or expand PAW for admin work, expand Defender + Sentinel monitoring with detections tuned to the observed adversary TTPs, and apply the least privilege model across the privileged tier. Verify: 100% of privileged accounts in PIM and behind phishing-resistant MFA; named PAW estate for admin work; new detections deployed for the specific TTPs seen.
  8. Transition to BAU - Hand off to a sustained security operations and improvement programme with a 90-day watch period, a documented lessons-learned, and committed investment in the gaps that allowed initial compromise.
Show full SKILL.md (386 more words)Show less

Guardrails

  • Engage qualified incident responders (e.g. Microsoft Incident Response) for any major incident. This is not a self-service exercise above a certain threshold.
  • Sequence eviction carefully - partial eviction warns the adversary and invites re- entrenchment. Plan, rehearse, then execute as one action.
  • Preserve forensic evidence before remediating where investigation, regulatory, or insurance obligations apply. Wiping is destruction of evidence.
  • Never act from compromised infrastructure - establish a trusted foundation and PAW before touching the adversary's territory.
  • Reset krbtgt twice with replication interval between resets - a single reset still leaves valid golden tickets in flight.
  • MFA without phishing-resistant factors is not enough post-AiTM-era. Move privileged users to FIDO2 / Windows Hello for Business / certificate-based auth.
  • PIM and least privilege are post-eviction non-negotiables - if the adversary got in via standing privilege, removing standing privilege is the eviction.

Common anti-patterns

  • Piecemeal eviction. Disabling one compromised account tips off the adversary, who pivots to the next persistence and digs deeper. Plan and execute as one coordinated action.
  • Acting from the compromised admin workstation. The adversary watches the response in real time and adapts. Always operate from PAW or equivalent.
  • Skipping krbtgt reset because "the password changed". krbtgt is the AD trust root - if it was harvested, every Kerberos ticket is forged-capable until reset (twice).
  • Forgetting service principals and app registrations. Modern Entra compromises persist via consent grants and app secrets long after user accounts are reset.
  • Declaring victory too early. Without a 90-day watch period and new detections tuned to the observed TTPs, you will not see the re-entry attempt.
  • No lessons learned, no investment commitment. The compromise will recur if the root cause (weak MFA, no PIM, flat network, no PAW) is not funded for remediation.

Example prompts

  • An attacker has Global Admin in our tenant right now. Walk me through evicting them.
  • Walk me through the Microsoft incident response process for a ransomware attack.
  • How do I evict an adversary from an Entra ID tenant without tipping them off?
  • What should I do in the first 24 hours after discovering a tenant compromise?
  • How do I harden the tenant after eviction so the attacker cannot return?
  • How do I rebuild trust in our admin accounts after a breach?

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/compromise-recovery of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Compromise Recovery next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compromise Recovery compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compromise Recovery this skillvinayaklatthe/microsoft-security-skills175—~2.4kAutomated safety check: PassMIT
UModel Root Cause Analysisalibaba/UnifiedModel415—~1.9kAutomated safety check: PassCustom licence
Learningskortix-ai/suna20k—~1.1kAutomated safety check: PassCustom licence
Axiom SRE Investigatoropenclaw/clawhub9.5k—~7.1kAutomated safety check: PassMIT
TMDb Integration Failure Fixeradamayoung/TMDb178—~2.7kAutomated safety check: PassApache-2.0
Incident Triage Harnessmadebyaris/advance-minimax-m3-cursor-rules126—~984Automated safety check: PassMIT

Similar skills

  • UModel Root Cause Analysis

    alibaba/UnifiedModel

    Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.

    415 GitHub stars~1.9k tokensUpdated 17 days ago
    DevOps & CloudAuto-check passed
  • Learnings

    kortix-ai/suna

    The project's episodic memory: a timestamped ledger of rules paid for with real outages and near-misses, one entry per incident.

    20k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Axiom SRE Investigator

    openclaw/clawhub

    Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.

    9.5k GitHub stars~7.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Diagnoses a failing scheduled TMDb Integration run, re-runs transient failures, and fixes real API drift on its own branch with a PR, merging it only when told to.

    178 GitHub stars~2.7k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Incident Triage Harness

    madebyaris/advance-minimax-m3-cursor-rules

    Walks an agent through an evidence-first incident investigation across logs, metrics, code and screenshots, from first symptom to the smallest safe mitigation.

    126 GitHub stars~984 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • APIOps Deployment for Azure APIM

    thomast1906/github-copilot-agent-skills

    Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.

    202 GitHub stars~3.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Compromise Recovery

What does Compromise Recovery do?

Guidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to…. Compromise Recovery is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for responding to and recovering from a significant identity/tenant compromise - regaining administrative control, evicting the adversary in a single coordinated action, and hardening to prevent reentry.

When should I use Compromise Recovery?

Compromise Recovery fits situations like: routine SOC investigation (use defender-xdr / sentinel); for preventive hardening with no active compromise (use security-architecture / entra-id).

How do I install Compromise Recovery in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill compromise-recovery -a claude-code`. Or copy the skill folder (skills/compromise-recovery in vinayaklatthe/microsoft-security-skills) into .claude/skills/compromise-recovery in your project. Claude Code loads it when a task matches its description.

How do I install Compromise Recovery in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill compromise-recovery -a codex`. Or copy the skill folder (skills/compromise-recovery in vinayaklatthe/microsoft-security-skills) into .agents/skills/compromise-recovery in your project. Codex loads it when a task matches its description.

Can I use Compromise Recovery in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill compromise-recovery -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compromise-recovery, .gemini/skills/compromise-recovery, .github/skills/compromise-recovery and .opencode/skills/compromise-recovery in your project.

What does Compromise Recovery need to run?

SKILL.md names no scripts, command-line tools or credentials: Compromise Recovery is instructions for the agent only.

Does Compromise Recovery access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and microsoft.com. This is read from the text; nothing was executed.

Is Compromise Recovery safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Compromise Recovery use?

Compromise Recovery is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compromise Recovery use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Compromise Recovery?

Skills that share tags, products or a category with Compromise Recovery: UModel Root Cause Analysis (alibaba/UnifiedModel, 415 stars), Learnings (kortix-ai/suna, 20k stars), Axiom SRE Investigator (openclaw/clawhub, 9.5k stars) and TMDb Integration Failure Fixer (adamayoung/TMDb, 178 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compromise Recovery?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.