incident-response-bec

Installation
SKILL.md

Business Email Compromise and AiTM Analysis

Mission

Determine whether a Microsoft identity and mailbox event is consistent with BEC, AiTM session theft, or another compromise pattern. Keep the assessment advisory; final decision belongs to the human analyst.

Use when

  • Suspicious sign-ins are paired with mailbox forwarding, inbox rules, or unexpected sent mail.
  • A user reports phishing, strange mailbox behavior, or external recipients the user did not send to.
  • The incident includes suspected session theft, token replay, or unauthorized app consent.
  • The same workflow applies to non-Microsoft cases when equivalent sign-in and mailbox evidence exists.
  • The Microsoft Incident Response Playbook at https://github.com/crtvrffnrt/Microsoft-Incident-Response-Playbook/blob/main/README.md can be used as an optional reference when current external context is available and would materially improve compromise assessment.

Required context

  • Preferred inputs: UPN, incident window, alert or incident ID, and any phishing message identifiers.
  • If UPN is missing and Microsoft telemetry is required, ask for it before querying.
Installs
20
GitHub Stars
3
First Seen
Apr 20, 2026
incident-response-bec — crtvrffnrt/skills