Simulated security analysis ยท 2025
Phishing Incident Investigation & Log-Based Detection
A practical SOC workflow demonstration from alert validation through response recommendations.
- Phishing analysis
- Log correlation
- MITRE ATT&CK
- SIEM detection
Scenario
A simulated phishing email containing a malicious embedded link reached a corporate inbox. The investigation validated the alert, reviewed potential credential abuse, and defined escalation and remediation steps.
Investigation
- Analyzed email headers for SPF and DKIM inconsistencies.
- Reviewed the linked domain, registration signals, and reputation.
- Checked authentication and web access logs for abnormal activity.
- Correlated timestamps and evaluated IP and geolocation anomalies.
Findings
- The linked domain was recently registered and suspicious.
- No credential submission or abnormal login pattern was confirmed.
- The event was classified as a contained phishing attempt.
MITRE ATT&CK mapping
- T1566 โ Phishing (Initial Access)
- T1078 โ Valid Accounts (potential risk scenario)
Response and detection improvement
- Documented the event as a true positive without confirmed compromise.
- Recommended a precautionary password reset and continued monitoring.
- Proposed correlating email delivery with failed or new-geolocation login activity.
- Recommended tuning thresholds to reduce false positives.