Email Security

zhaoxuya520/reverse-skill/skills/email-security

by zhaoxuya520cab634bd855fNo license40K starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 2 weeks ago

Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.

Instructions onlySecurity
AI-generated overview

Guides authorized email security review: phishing analysis, SPF/DKIM/DMARC header authentication, BEC patterns and mailbox token abuse.

What it does
Provides a structured workflow for reviewing suspicious email, covering full raw header inspection, Received chain and From/Return-Path consistency, SPF/DKIM/DMARC alignment, URL and attachment checks, and brand impersonation and reply-address differences. It also covers tenant-side controls such as anti-phishing policies, external tagging, MFA and OAuth app consent, and points to a bundled email authentication checklist reference. Outputs are analysis conclusions and detection-ready indicators rather than files.
When to use it
Use it when performing an authorized email security review, such as dissecting a phishing sample, assessing SPF/DKIM/DMARC configuration, investigating business email compromise patterns, or examining OAuth app phishing and mailbox token abuse. It assumes authorization for the sample or tenant being reviewed.
Requirements
Instructions only; no scripts are shipped. It references a bundled checklist file and expects access to raw email headers, DNS lookup tools such as dig or nslookup, URL and attachment sandboxing services, and a tenant management console for policy review.

Email Security & Phishing Analysis

ACTION REQUIRED(读完后立刻执行)

  1. NOW: 确认授权(分析样本邮件 / 租户配置评审)
  2. NOW: 不向真实用户二次投递恶意样本
  3. ACT: 头认证 → 内容/URL → 附件沙箱 → 租户控制面建议

适用场景

  • 钓鱼邮件拆解与 IOC
  • SPF/DKIM/DMARC 配置评估
  • BEC 商务邮件欺诈模式
  • OAuth 应用钓鱼 / 邮箱令牌滥用(联合 llm/cloud 身份)
  • 安全意识演练设计(授权)

工作流

text
□ 完整原始头:Received 链、From/Return-Path 一致性□ SPF/DKIM/DMARC 对齐结果□ URL 沙箱与附件静态(联合 malware-analysis)□ 仿冒品牌与回复地址差异□ 租户:反钓鱼策略、外部标记、MFA、OAuth app 同意

工具链

工具用途
邮件客户端「查看源」头
dig/nslookupSPF/DMARC 记录
urlscan / 沙箱链接与附件
租户管理中心策略

参考

  • references/email-auth-checklist.md
  • ../malware-analysis/ ../attack-chain/(钓鱼阶段) ../windows-ad/(令牌)

路由上下文

上游: MASTER R36
MUST NOT: 未授权对第三方域群发测试钓鱼

任务完成自检

  • 头认证结论是否完整?
  • IOC 是否可检测化(联合 threat-hunting)?
  • Checklist?

Source and attribution

Source:zhaoxuya520/reverse-skillinskills/email-securityat commitcab634b

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal