incident-response-bec
Installation
SKILL.md
Business Email Compromise and AiTM Analysis
Mission
Determine whether a Microsoft identity and mailbox event is consistent with BEC, AiTM session theft, or another compromise pattern. Keep the assessment advisory; final decision belongs to the human analyst.
Use when
- Suspicious sign-ins are paired with mailbox forwarding, inbox rules, or unexpected sent mail.
- A user reports phishing, strange mailbox behavior, or external recipients the user did not send to.
- The incident includes suspected session theft, token replay, or unauthorized app consent.
- The same workflow applies to non-Microsoft cases when equivalent sign-in and mailbox evidence exists.
- The Microsoft Incident Response Playbook at
https://github.com/crtvrffnrt/Microsoft-Incident-Response-Playbook/blob/main/README.mdcan be used as an optional reference when current external context is available and would materially improve compromise assessment.
Required context
- Preferred inputs: UPN, incident window, alert or incident ID, and any phishing message identifiers.
- If UPN is missing and Microsoft telemetry is required, ask for it before querying.