🛡️
QualityGo

Office 365 Audit Log Analysis

by xalgord

Office 365 Audit Log Analysis is a Quality skill for Claude Code, published by xalgord in xalgorix.

852 stars153 forkson xalgord/xalgorixAdded 2026/08/12+1% in starsRepository updated 2026/08/11
ai-agentai-securityautomationautonomous-pentestingbug-bountycybersecurityethical-hackinggolangpenetration-testingpentestpentesting-toolsreconsecuritysecurity-researchsecurity-toolstypescriptvulnerability-detectionvulnerability-scanner
Install in seconds
Install Office 365 Audit Log Analysis
Copy Office 365 Audit Log Analysis into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/xalgorix/xalgorix/tree/main/internal/tools/skills/data/cloud-security/analyzing-office365-audit-logs-for-compromise ~/.claude/skills/analyzing-office365-audit-logs-for-compromise

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/xalgorix/xalgorix.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
internal/tools/skills/data/cloud-security/analyzing-office365-audit-logs-for-compromise/SKILL.md in xalgord/xalgorix
Installs to
~/.claude/skills/analyzing-office365-audit-logs-for-compromise
Collection
One of 51 skills cataloged from this repository
Category
Quality1354 skills

What Office 365 Audit Log Analysis does

Office 365 Audit Log Analysis queries Microsoft Graph Unified Audit Logs to find mailbox forwarding, delegation changes, OAuth consent grants, and other compromise indicators. Use it during incident response or threat hunting for business email compromise.

Office 365 Audit Log Analysis is cataloged under Quality on DirSkills. Office 365 Audit Log Analysis comes from a repository tagged ai-agent, ai-security, automation, autonomous-pentesting and bug-bounty.

Documentation

README

Analyzing Office 365 Audit Logs for Compromise

Overview

Business Email Compromise (BEC) attacks often leave traces in Office 365 audit logs: suspicious inbox rule creation, email forwarding to external addresses, mailbox delegation changes, and unauthorized OAuth application consent grants. This skill uses the Microsoft Graph API to query the Unified Audit Log, enumerate inbox rules across mailboxes, detect forwarding configurations, and identify compromised account indicators.

When to Use

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Office 365 Audit Log Analysis

  • What else does xalgord publish alongside Office 365 Audit Log Analysis?

    Office 365 Audit Log Analysis is one of 51 skills that DirSkills catalogs from xalgord/xalgorix, the repository it ships in. Its siblings there include AFL++ Fuzzing, AI Security Guardrails and AI-Assisted Vulnerability Discovery. Each one is a separate skill with its own page in this directory, installs the same way Office 365 Audit Log Analysis does, and is maintained by xalgord in that same repository. The rest of the collection is listed on the xalgord/xalgorix page.

  • How does Office 365 Audit Log Analysis compare to other Quality skills?

    Office 365 Audit Log Analysis ranks #933 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Office 365 Audit Log Analysis against them. Open each page to compare what they document and how they install.

More from xalgord/xalgorix

Office 365 Audit Log Analysis is one of 51 skills cataloged on DirSkills from xalgord/xalgorix.

See all 51 skills