Phishing Incident Investigation & Log-Based Detection

A practical SOC workflow demonstration from alert validation through response recommendations.

  • Phishing analysis
  • Log correlation
  • MITRE ATT&CK
  • SIEM detection

Scenario

A simulated phishing email containing a malicious embedded link reached a corporate inbox. The investigation validated the alert, reviewed potential credential abuse, and defined escalation and remediation steps.

Investigation

  • Analyzed email headers for SPF and DKIM inconsistencies.
  • Reviewed the linked domain, registration signals, and reputation.
  • Checked authentication and web access logs for abnormal activity.
  • Correlated timestamps and evaluated IP and geolocation anomalies.

Findings

  • The linked domain was recently registered and suspicious.
  • No credential submission or abnormal login pattern was confirmed.
  • The event was classified as a contained phishing attempt.

MITRE ATT&CK mapping

  • T1566 โ€” Phishing (Initial Access)
  • T1078 โ€” Valid Accounts (potential risk scenario)

Response and detection improvement

  • Documented the event as a true positive without confirmed compromise.
  • Recommended a precautionary password reset and continued monitoring.
  • Proposed correlating email delivery with failed or new-geolocation login activity.
  • Recommended tuning thresholds to reduce false positives.