email-and-collaboration

Encode Microsoft 365 email and collaboration telemetry for threat detection.

4|1|Updated Apr 28, 2026
One-click install
npx skills add https://github.com/OpenTideHQ/AgentTide --skill email-and-collaboration
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: email-and-collaboration
Source: https://github.com/OpenTideHQ/AgentTide/tree/main/skills/email-and-collaboration
Command: npx skills add https://github.com/OpenTideHQ/AgentTide --skill email-and-collaboration

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill encodes Microsoft 365 email and collaboration telemetry knowledge to detect BEC, phishing, data exfiltration, and insider threats across Exchange Online, SharePoint/OneDrive, and Teams.

Core Features & Use Cases

  • Encodes detection patterns for mail flow changes (transport rules, journal rules), mailbox delegation and forwarding, OAuth app permissions on mailboxes, SharePoint/OneDrive external sharing, Teams guest access, and UAL event patterns.
  • Supports near-real-time detection design by mapping telemetry events to SIEM cues and building end-to-end detection chains across email and collaboration surfaces.
  • Use cases include detecting BEC, phishing campaigns, data exfiltration via collaboration tools, and insider threat indicators.

Quick Start

Analyze your organization's Microsoft 365 telemetry description and generate detection rules for email-based attacks and collaboration data leaks.

Frequently Asked Questions about email-and-collaboration

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect Business Email Compromise (BEC) and phishing in M365?

To detect BEC and phishing in M365, you analyze telemetry from mail flow changes, mailbox delegation, and forwarding rules to build end-to-end detection chains across Exchange Online and Teams.

What M365 telemetry is needed to identify data exfiltration in SharePoint and OneDrive?

Identifying data exfiltration in SharePoint and OneDrive requires telemetry from external sharing activities, OAuth app permissions, and Unified Audit Log events to map indicators to SIEM detection cues.

How can I map Microsoft 365 collaboration events to SIEM detection rules?

You map M365 collaboration events to SIEM detection rules by encoding telemetry patterns from Teams guest access and SharePoint sharing into YAML frontmatter with Markdown operational instructions for on-demand loading.

Does this approach monitor insider threat indicators across Exchange Online and Teams?

Yes, this approach monitors insider threat indicators by analyzing mailbox forwarding configurations, OAuth app permissions, and Teams guest access telemetry to detect unauthorized data movement across collaboration surfaces.

What is the best way to detect malicious mail flow changes in Exchange Online?

The best way to detect malicious mail flow changes in Exchange Online is to monitor transport rules, journal rules, and mailbox delegation telemetry to identify unauthorized modifications and suspicious forwarding configurations.