competition-mailbox-abuse

Correlate consent, delegation, forwarding, and mailbox configurations to trace abuse paths.

4|Updated Apr 9, 2026
One-click install
npx skills add https://github.com/xjtu-wang/DigAgent --skill competition-mailbox-abuse
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: competition-mailbox-abuse
Source: https://github.com/xjtu-wang/DigAgent/tree/main/.agents/skills/competition-mailbox-abuse
Command: npx skills add https://github.com/xjtu-wang/DigAgent --skill competition-mailbox-abuse

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Tracing mailbox abuse paths, OAuth consent flows, and mailbox-side mutations to determine how phishing, delegation, or forwarding rules enable persistence or privilege in enterprise environments.

Core Features & Use Cases

  • Trace consent grants, forwarding rules, shared mailbox permissions, and mailbox rules to map attacker paths to decisive mail-flow effects.
  • Correlate identity, token, and mailbox events with message traces to prove persistence, exfiltration, or privilege escalation.
  • Use for incident response and security auditing in large organizations with mailbox-heavy abuse scenarios.

Quick Start

Decide the active path (phishing-to-consent, token-to-mailbox, rule-based persistence, or transport-level mail rerouting) and record all related evidence in compact blocks.

Frequently Asked Questions about competition-mailbox-abuse

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I trace mailbox abuse paths involving OAuth consent grants and forwarding rules?

Trace mailbox abuse by correlating OAuth consent grants, delegation, forwarding rules, and mailbox configurations with decisive mail-flow events to map attacker paths and prove persistence or exfiltration.

What is the best way to investigate shared mailbox access during an enterprise incident response?

Investigate shared mailbox access by correlating identity, token, and mailbox events with message traces to map precise identity and action sequences that prove privilege escalation.

Can I use this to correlate transport rules with message traces for security auditing?

Yes, you can correlate transport rules and inbox rules with message traces during security auditing to verify mail rerouting and generate compact, replayable evidence sequences.

How do I map attacker persistence mechanisms using mailbox-side mutations?

Map attacker persistence by tracing mailbox-side mutations like inbox rules and consent grants, aligning evidence to show how phishing or delegation enables continued access.

Does this approach work for large organizations with mailbox-heavy abuse scenarios?

Yes, this approach is designed for incident response and security auditing in large organizations, satisfying requirements for precise identity, mailbox, and action mapping in mailbox-heavy abuse scenarios.

How do I start tracing a phishing-to-consent attack path?

Start tracing a phishing-to-consent attack path by identifying the active path, then recording all related consent, delegation, and mail-flow evidence in compact blocks for replayable sequencing.