acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors,
$ npx -y skills add Mikaru0Mystic/sectinel --skill detecting-business-email-compromise --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/detecting-business-email-compromiseContext preview
The summary Claude sees to decide when to auto-load this skill.
Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors,
name: detecting-business-email-compromise description: Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data, domain: cybersecurity subdomain: phishing-defense tags: - phishing - email-security - social-engineering - dmarc - awareness - bec - fraud version: '1.0' author: mahipal license: Apache-2.0 atlas_techniques: - AML.T0052 - AML.T0088 nist_ai_rmf: - GOVERN-6.2 - MAP-5.2 d3fend_techniques: - Restore Object - Restore Configuration - Application Configuration Hardening - Application Hardening - Disable Remote Access nist_csf: - PR.AT-01 - DE.CM-09 - RS.CO-02 - DE.AE-02
Business Email Compromise (BEC) is a sophisticated fraud scheme where attackers impersonate executives, vendors, or trusted partners to trick employees into transferring funds, sharing sensitive data, or changing payment details. Unlike traditional phishing, BEC often contains no malicious links or attachments, relying purely on social engineering. This skill covers detection techniques using email gateway rules, behavioral analytics, and financial process controls.
1. **CEO Fraud**: Attacker impersonates CEO, requests urgent wire transfer 2. **Account Compromise**: Employee email compromised, used to request payments from vendors 3. **False Invoice Scheme**: Fake invoices from "vendor" with changed bank details 4. **Attorney Impersonation**: Impersonates legal counsel for urgent confidential transfers 5. **Data Theft**: Requests W-2, tax forms, or PII from HR
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative