npx claudepluginhub plurigrid/asi --plugin asiThis skill uses the workspace's default tool permissions.
Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint, Mimecast, and Barracuda provide advanced detection capabilities including behavioral analysis, URL detonation, attachment sandboxing, and impersonation detection. This skill covers configuring the...
Guides configuration of email gateways like Microsoft Defender and Proofpoint to detect spearphishing via impersonation protection, URL detonation, and behavioral analysis. For incident response and threat hunting.
Configures email security gateways like Microsoft Defender, Proofpoint, Mimecast, Barracuda to detect spearphishing via impersonation protection, URL detonation, attachment sandbox, and custom rules. Useful for targeted phishing defense.
Hunts spearphishing indicators across email logs, endpoint telemetry, and network data using SIEM/EDR tools like Splunk, CrowdStrike, and Elastic to detect targeted attacks.
Share bugs, ideas, or general feedback.
Spearphishing targets specific individuals using personalized, researched content that bypasses generic spam filters. Email security gateways (SEGs) like Microsoft Defender for Office 365, Proofpoint, Mimecast, and Barracuda provide advanced detection capabilities including behavioral analysis, URL detonation, attachment sandboxing, and impersonation detection. This skill covers configuring these gateways to detect and block targeted phishing attacks.
Microsoft Defender for Office 365:
Security > Anti-phishing policies > Impersonation settings
- Enable user impersonation protection for VIPs
- Enable domain impersonation protection
- Add protected users (CEO, CFO, HR Director)
- Set action: Quarantine message
Proofpoint:
Email Protection > Impostor Classifier
- Enable display name spoofing detection
- Configure lookalike domain detection
- Set Impostor threshold sensitivity
Use the scripts/process.py to analyze email gateway logs, identify spearphishing patterns, and generate custom detection rules.