Token导航 LogoToken导航TokenDH.com
运维和基础设施需要联网github未标认证来源可访问许可证需确认审计提醒

detecting-business-email-compromise-with-ai检测商业电子邮件与 AI 的妥协

Agent Skill

detecting-business-email-compromise-with-ai 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

210

周安装

9

GitHub Stars

5,917

下载量

73
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:detecting-business-email-compromise-with-ai(检测商业电子邮件与 AI 的妥协)
来源仓库:https://github.com/mukul975/anthropic-cybersecurity-skills
仓库路径:skills/detecting-business-email-compromise-with-ai
安装命令:
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill detecting-business-email-compromise-with-ai
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill detecting-business-email-compromise-with-ai

简介

利用 AI 模型检测高级别商业邮件欺诈,提升对无恶意载荷攻击的识别率。

  • 适用于 NLP 驱动的写作风格分析、语气异常与行为模式偏离检测。
  • 可集成 BERT 等预训练模型,准确率达 98.65% 以上。
  • 需部署 ML 推理环境与标注数据,注意模型偏见与误报风险控制。
  • detecting-business-email-compromise-with-ai 属于运维和基础设施类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Detecting Business Email Compromise with AI

Overview

AI-powered BEC detection uses machine learning, NLP, and behavioral analytics to identify sophisticated impersonation attacks that contain no malicious links or attachments. Traditional rule-based filters miss these attacks because BEC relies purely on social engineering. Modern AI approaches analyze writing style, tone, vocabulary, grammatical patterns, and behavioral context to determine if an email genuinely comes from the stated sender. BERT-based models achieve 98.65% accuracy in BEC detection, and AI-enhanced platforms show a 25% increase in phishing identification over keyword-based rules.

When to Use

  • When investigating security incidents that require detecting business email compromise with ai
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • AI-powered email security platform (Abnormal Security, Tessian, Microsoft Defender)
  • Historical email data for baseline training (minimum 30 days)
  • Integration with email platform (Microsoft 365 or Google Workspace)
  • SIEM for alert correlation and investigation
  • Understanding of BEC attack types (FBI IC3 classification)

Workflow

Step 1: Deploy AI Email Security Platform

  • Select API-based solution (Abnormal Security, Tessian, Ironscales) or enhance existing SEG
  • Connect to Microsoft Graph API or Google Workspace API
  • Allow 48-hour baseline learning period on historical email data
  • Configure integration to scan inbound, outbound, and internal email
  • Verify API permissions for message access and remediation

Step 2: Configure Behavioral Baselines

  • AI learns normal communication patterns: who emails whom, frequency, tone
  • Establish writing style profiles for each user (vocabulary, sentence structure)
  • Map typical request types per role (finance processes payments, HR handles PII)
  • Baseline email metadata: typical sending times, devices, locations
  • Flag deviations from established baselines as anomalous

Step 3: Train NLP Models for BEC Detection

  • Deploy transformer-based models (BERT, GPT) for email content analysis
  • Detect urgency and manipulation language patterns
  • Identify mismatches between sender identity and writing style
  • Analyze sentiment shifts indicating social engineering pressure
  • Classify email intent: information request, payment request, credential request

Step 4: Configure Detection Policies

  • VIP impersonation: AI compares new email against known executive communication patterns
  • Vendor impersonation: detect payment change requests from vendor lookalike domains
  • Account compromise: detect sudden changes in employee email behavior
  • Supply chain BEC: monitor for impersonation of trusted partners
  • Configure confidence thresholds for auto-block vs. warning banner vs. analyst review

Step 5: Integrate with Response Workflow

  • Auto-quarantine high-confidence BEC detections
  • Add warning banners for moderate-confidence detections
  • Route suspicious emails to SOC analyst queue for review
  • Integrate with SOAR for automated response playbooks
  • Feed BEC verdicts back into training data for model improvement

Tools & Resources

  • Abnormal Security: API-based AI email security with behavioral analysis
  • Microsoft Defender for O365: Built-in AI anti-BEC with Impostor Classifier
  • Tessian (Proofpoint): AI-powered email security with human layer protection
  • Ironscales: AI + human-in-the-loop BEC detection
  • Darktrace Email: Self-learning AI for email threat detection

Validation

  • AI detects test BEC email with no malicious indicators (pure social engineering)
  • Writing style analysis identifies impersonation of known executive
  • Behavioral baseline flags unusual payment request from compromised account
  • NLP correctly classifies urgency manipulation in test scenario
  • False positive rate below 0.05% after baseline training
  • Detection rate exceeds traditional rule-based filters by 25%+

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

35.16%
按下载量换算26

Claude

27.31%
按下载量换算20

Cursor

20.6%
按下载量换算15

Gemini CLI

9.65%
按下载量换算7

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills