Skip to content
Security
Skill

/conducting-phishing-incident-response

Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise,

From plugin
sectinel
11200 skills
Install
$ npx -y skills add Mikaru0Mystic/sectinel --skill conducting-phishing-incident-response --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/conducting-phishing-incident-response

Context preview

The summary Claude sees to decide when to auto-load this skill.

Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise,

SKILL.md

conducting-phishing-incident-response.SKILL.md
name: conducting-phishing-incident-response
description: 'Responds to phishing incidents by analyzing reported emails, extracting indicators, assessing credential compromise,
  quarantining malicious messages across the organization, and remediating affected accounts. Covers email header analysis,
  URL/attachment sandboxing, and mailbox-wide purge operations. Activates for requests involving phishing response, email
  incident, credential phishing, spear phishing investigation, or phishing remediation.

  '
domain: cybersecurity
subdomain: incident-response
tags:
- phishing-response
- email-security
- credential-compromise
- email-header-analysis
- mailbox-remediation
mitre_attack:
- T1566
- T1204
- T1534
- T1598
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- RS.MA-01
- RS.MA-02
- RS.AN-03
- RC.RP-01

Conducting Phishing Incident Response

When to Use

  • A user reports receiving a suspicious email via the phishing report button or abuse mailbox
  • Email gateway detects a malicious email that bypassed initial filtering
  • Threat intelligence indicates an active phishing campaign targeting the organization
  • A user confirms they clicked a link or opened an attachment from a suspicious email
  • Credentials have been entered on a suspected phishing page

**Do not use** for business email compromise (BEC) involving compromised internal accounts; use BEC response procedures which focus on account takeover investigation.

Prerequisites

  • Email security gateway with message trace and quarantine capabilities (Microsoft Defender for Office 365, Proofpoint, Mimecast)
  • Microsoft 365 admin access or Google Workspace admin for mailbox search and purge
  • Malware sandbox for attachment and URL analysis (ANY.RUN, Joe Sandbox, Hybrid Analysis)
  • Email header analysis tools (MXToolbox Header Analyzer, Google Admin Toolbox)
  • Identity provider access for account remediation (Azure AD, Okta, Duo)
  • Phishing report intake process (dedicated mailbox or integrated report button)

Workflow

Step 1: Receive and Triage the Phishing Report

Evaluate the reported email to determine if it is malicious:

  • Extract the email as an .EML or .MSG file (preserves headers)
  • Analyze email headers to determine the true sender, relay path, and authentication results
Email Header Analysis Checklist:
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Return-Path:     billing@spoofed-domain[.]com
From:            "IT Support" <support@corp-lookalike[.]com>
Reply-To:        attacker@gmail[.]com (different from From)
SPF:             FAIL (sender IP not authorized for domain)
DKIM:            FAIL (signature invalid)
DMARC:           FAIL (policy: none - no enforcement)
Received:        from mail.attacker-infra[.]net [45.33.x.x]
X-Originating-IP: 45.33.x.x
Message-ID:      <random@attacker-infra.net>

Classification criteria:

  • **Confirmed Phishing**: Malicious URL/attachment, spoofed sender, credential harvesting page
  • **Suspicious**: Anomalous headers but no confirmed malicious content
  • **Spam/Marketing**: Unwanted but not malicious
  • **Legitimate**: Not a phishing email (false report)

Step 2: Analyze Malicious Content

Examine URLs and attachments in a safe environment:

**URL Analysis:**

  • Check URL against VirusTotal, URLscan.io, and Google Safe Browsing
  • Open URL in a sandbox browser to capture the landing page
  • Check if the URL redirects to a credential harvesting page
  • Identify the phishing kit type (Microsoft 365 login clone, Okta clone, generic)
  • Determine if the phishing page is still active

**Attachment Analysis:**

  • Calculate file hash (SHA-256) and check against VirusTotal
  • Detonate in sandbox (ANY.RUN, Joe Sandbox)
  • Analyze document for macros (olevba for Office files)
  • Check for embedded exploits (CVE exploitation in document parsers)

Step 3: Determine Scope of Impact

Identify all recipients and assess who interacted with the phishing email:

Scope Assessment:
━━━━━━━━━━━━━━━━
Total Recipients:     47 users
Delivered to Inbox:   38 users (9 caught by email gateway)
Opened Email:         24 users (email tracking pixel data)
Clicked Link:         8 users (proxy/firewall logs)
Entered Credentials:  3 users (phishing page submitted form data)
Opened Attachment:    2 users (EDR process execution telemetry)

Search methods:

  • Microsoft 365: Use Threat Explorer or Content Search to find all instances of the email
  • Google Workspace: Use Admin Console > Investigation tool for message search
  • Proxy logs: Search for connections to the phishing URL from internal IPs
  • EDR: Search for attachment file hash execution across all endpoints

Step 4: Contain the Threat

Execute containment actions based on impact assessment:

**Email Containment:**

  • Purge the phishing email from all mailboxes using Microsoft 365 Content Search and Purge or Google Workspace Admin delete
  • Block the sender domain at the email gateway
  • Add the phishing URL to the web proxy blocklist
  • Add attachment hash to email gateway and EDR blocklists

**Account Containment (for users who entered credentials):**

  • Force password reset immediately
  • Revoke all active sessions and OAuth tokens
  • Enable or re-verify MFA enrollment
  • Review mailbox rules for attacker-created forwarding rules
  • Check for unauthorized OAuth application grants
  • Review recent sign-in activity for suspicious locations
# Microsoft 365: Revoke sessions and reset password
Connect-AzureAD
Revoke-AzureADUserAllRefreshToken -ObjectId "user@corp.com"
Set-AzureADUserPassword -ObjectId "user@corp.com" -ForceChangePasswordNextLogin $true

# Check for mailbox forwarding rules
Get-InboxRule -Mailbox "user@corp.com" | Where-Object {$_.ForwardTo -or $_.RedirectTo}

# Remove suspicious forwarding rules
Remove-InboxRule -Mailbox "user@corp.com" -Identity "Rule Name"

Step 5: Eradicate and Recover

Remove all traces of the phishing attack:

  • Confirm email purge completed successfully across all mailboxes
  • Verify compr
Read more
Ships withsectinel

Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.

Get the whole plugin

Other skills on sectinel.