What problem does it solve?
When a phishing email reaches users, responders must quickly determine who received it, who clicked, and whose credentials were stolen, then purge the message and secure accounts before attackers exploit stolen sessions. This Skill provides a structured end-to-end workflow for triaging reported phishing emails, scoping impact, containing the threat, and remediating compromised accounts.
Core Features & Use Cases
- Email Triage and Header Analysis: Classify reported emails using SPF, DKIM, DMARC, Return-Path, and Received header inspection to confirm phishing versus spam or false reports.
- Impact Scoping and Containment: Search all mailboxes via Microsoft 365 Content Search or Google Workspace investigation tools, cross-reference proxy and EDR telemetry, then purge messages and block sender domains, URLs, and attachment hashes.
- Account Remediation: Reset passwords, revoke sessions and OAuth tokens, remove malicious inbox forwarding rules, and verify MFA for users who entered credentials, including AiTM (Evilginx-style) session theft scenarios.
- Use Case: A user reports a QR-code email claiming MFA re-enrollment is required. Follow the workflow to decode the QR URL in a sandbox, identify the AiTM credential harvester, find all 47 recipients, purge the email, revoke sessions for the 3 users who entered credentials, and produce a structured incident report.
Quick Start
Respond to the reported phishing email in the attached EML file by analyzing its headers, scoping affected mailboxes, and generating a containment and remediation plan.