Skip to main content
ClaudeWave
Skill15.5k repo starsupdated 11d ago

analyzing-office365-audit-logs-for-compromise

This skill queries Microsoft Office 365 Unified Audit Logs via the Microsoft Graph API to detect indicators of business email compromise, including suspicious inbox rule creation, email forwarding to external addresses, unauthorized mailbox delegation changes, and anomalous OAuth application consent grants. Use it when investigating security incidents, building threat detection rules, or performing threat hunting for Office 365 account compromise.

Install in Claude Code
Copy
git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills /tmp/analyzing-office365-audit-logs-for-compromise && cp -r /tmp/analyzing-office365-audit-logs-for-compromise/skills/analyzing-office365-audit-logs-for-compromise ~/.claude/skills/analyzing-office365-audit-logs-for-compromise
Then start a new Claude Code session; the skill loads automatically.

SKILL.md

# Analyzing Office 365 Audit Logs for Compromise

## Overview

Business Email Compromise (BEC) attacks often leave traces in Office 365 audit logs: suspicious inbox rule creation, email forwarding to external addresses, mailbox delegation changes, and unauthorized OAuth application consent grants. This skill uses the Microsoft Graph API to query the Unified Audit Log, enumerate inbox rules across mailboxes, detect forwarding configurations, and identify compromised account indicators.


## When to Use

- When investigating security incidents that require analyzing office365 audit logs for compromise
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques

## Prerequisites

- Azure AD app registration with `AuditLog.Read.All`, `MailboxSettings.Read`, `Mail.Read` (application permissions)
- Python 3.9+ with `msal`, `requests`
- Client secret or certificate for authentication
- Global Reader or Security Reader role

## Steps

1. Authenticate to Microsoft Graph using MSAL client credentials flow
2. Query Unified Audit Log for suspicious operations (Set-Mailbox, New-InboxRule)
3. Enumerate inbox rules across mailboxes and flag forwarding rules
4. Detect mailbox delegation changes (Add-MailboxPermission)
5. Identify OAuth consent grants to suspicious applications
6. Check for suspicious sign-in patterns from audit logs
7. Generate compromise indicator report with timeline

## Expected Output

- JSON report listing forwarding rules, delegation changes, OAuth grants, and suspicious audit events with risk scores
- Timeline of compromise indicators with affected mailboxes