youlianvr

email-security

Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.

youlianvr 1 1 Updated 2d ago

Resources

1
GitHub

Install

npx skillscat add youlianvr/oper-share/email-security

Install via the SkillsCat registry.

SKILL.md

Email Security & Phishing Analysis

ACTION REQUIRED (execute immediately after reading)

  1. NOW: confirmAuthorization(Analysissample邮件 / tenantConfigurationReview)

  2. NOW: nottorealUser二次投递Malicioussample

  3. ACT: HeaderAuthentication → inner容/URL → attachmentsandbox → tenantControl surfaceSuggestion

Scope

  • 钓鱼邮件拆解and IOC

  • SPF/DKIM/DMARC ConfigurationAssessment

  • BEC 商务邮件欺诈 pattern

  • OAuth 应use钓鱼 / emailTokenAbuse (joint llm/cloud Identity)

  • Security意识演练设计(Authorization)

Workflow




□ completeoriginal始Header:Received  chain、From/Return-Path 一致性



□ SPF/DKIM/DMARC to齐Result



□ URL sandboxandattachmentStatic (joint malware-analysis)



□ 仿冒品牌andReply地址差异



□ tenant:反钓鱼Policy、outer partLabel、MFA、OAuth app 同意


Toolchain

| Tool | purpose |

|------|------|

| 邮件客户side「View源」 | Header |

| dig/nslookup | SPF/DMARC record |

| urlscan / sandbox | Linkandattachment |

| tenantManagementin心 | Policy |

References

  • references/email-auth-checklist.md

  • ../malware-analysis/ ../attack-chain/(钓鱼Phase) ../windows-ad/(Token)

Routing context

Upstream: MASTER R36

MUST NOT: notAuthorizationto第三方domain群发Testing钓鱼

Task completion checklist

  • HeaderAuthentication结论whethercomplete?

  • IOC whethercanDetectionize (joint threat-hunting)?

  • Checklist?

Categories