Skip to content

opentidehq/opentide-detection-skills

v1.0.0EUPL-1.2

Detection engineering skills for OpenTide — TVM, DOM, and MDR authoring, hunt-to-rule workflows, MITRE ATT&CK, platform query languages, and defensive internals — with the OpenTide MCP server.

email-and-collaboration

M365 email and collaboration security telemetry for detection engineering — Exchange Online mail flow (transport rules, journaling, DLP), mailbox delegation and forwarding rules, OAuth app permissions on mailboxes, SharePoint/OneDrive external sharing, Teams guest access, Purview Unified Audit Log (UAL) event types, MailItemsAccessed semantics, and BEC/phishing detection patterns. Use when authoring detections targeting email-based attacks, business email compromise, data exfiltration via collaboration tools, or insider threat indicators.

Read SKILL.md at the source

Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.

Files

Every link opens the file at its source, pinned to the revision this page describes.