🎯 Goal

The goal for today was to deepen my understanding of phishing attacks, which remain one of the most common initial access techniques used by attackers.

Instead of focusing only on the social engineering aspect, I explored:

  • how phishing campaigns work technically
  • how organizations detect them
  • what telemetry defenders use to investigate them

This is important because phishing frequently leads to:

  • credential theft
  • malware infection
  • account compromise
  • initial access into corporate environments

🛠 What I Did

Today I studied the mechanics behind phishing attacks and how companies defend against them.

Key topics explored:

  • how phishing emails trick users
  • email infrastructure used in attacks
  • security controls designed to detect spoofed emails

Phishing is fundamentally a social engineering attack where the attacker impersonates something trusted.

Common examples include attackers pretending to be:

  • a bank
  • Microsoft or Google
  • Amazon
  • a company IT department
  • a manager or executive

The attacker then attempts to convince the victim to:

  • click a malicious link
  • download a malicious attachment
  • reveal credentials or sensitive data

🔗 Key Cybersecurity Connections

Phishing is often the first stage of larger attacks.

A typical attack chain might look like:

Phishing email
↓
Victim enters credentials on fake page
↓
Attacker gains account access
↓
Attacker logs into company systems
↓
Lateral movement begins

Because of this, detecting phishing attempts early is critical.


🔍 Investigation Questions

If a phishing alert appeared in security telemetry, a SOC analyst might ask:

  • What email address and domain sent the message?
  • Did the email pass SPF, DKIM, and DMARC authentication checks?
  • Is the sender domain newly registered or suspiciously similar to a legitimate domain?
  • Did multiple employees receive the same email?
  • Did any users click the link or download attachments?
  • Were credentials entered on a suspicious webpage following the email?

These questions help analysts determine whether the message is part of a larger phishing campaign or targeted attack.


🚨 Detection Opportunities

Possible detection strategies for phishing attacks include:

  • monitoring SPF, DKIM, and DMARC failures
  • detecting look-alike or newly registered domains
  • correlating URLs with threat intelligence feeds
  • alerting when multiple employees receive similar suspicious emails
  • monitoring authentication logs for login attempts following phishing emails

Telemetry sources commonly used include:

  • email gateway logs
  • DNS logs
  • proxy logs
  • authentication logs
  • endpoint browser telemetry.

🧭 MITRE ATT&CK Techniques

Phishing attacks are associated with several MITRE ATT&CK techniques:

  • T1566 – Phishing
  • T1566.001 – Spearphishing Attachment
  • T1566.002 – Spearphishing Link
  • T1204 – User Execution

These techniques describe how attackers trick users into executing malicious actions that lead to initial compromise.


📡 Email Security Layers

Organizations use several defensive layers to detect phishing.

Email Security Gateways

Examples include:

  • Proofpoint
  • Mimecast
  • Microsoft Defender for Office 365

These systems scan incoming emails for:

  • malicious links
  • suspicious attachments
  • spoofed senders
  • known malicious domains

Domain Authentication Technologies

Three important mechanisms help detect spoofed email senders:

SPF (Sender Policy Framework)
Defines which mail servers are allowed to send email for a domain.

DKIM (DomainKeys Identified Mail)
Adds a cryptographic signature to verify the message integrity.

DMARC (Domain-based Message Authentication, Reporting & Conformance)
Combines SPF and DKIM to define how receiving servers handle failures.

These technologies help prevent attackers from impersonating legitimate domains.


⚠ Challenges

The most challenging part was understanding that phishing detection is not just about spotting suspicious emails manually.

In real organizations, detection relies on:

  • automated filtering systems
  • reputation databases
  • authentication failures
  • behavioral analysis

Investigating phishing often requires analyzing multiple log sources.


📚 What I Learned

Key takeaways:

  • phishing remains one of the most effective attack methods
  • attackers rely on trust and urgency
  • technical defenses rely heavily on email authentication and filtering

Understanding phishing from both perspectives helps analysts:

  • detect malicious campaigns
  • investigate suspicious emails
  • prevent credential theft.

➡ Next Steps

Next I want to explore:

  • how phishing emails appear in security logs
  • how SOC analysts investigate suspicious email events
  • how malicious domains are detected

🧠 Reflection

Phishing is a reminder that cybersecurity is not only technical — it also involves human psychology.

Even highly secure systems can be compromised if a user is tricked into giving access.

This reinforces the importance of combining:

  • technical defenses
  • monitoring
  • user awareness training.

🧩 Lessons Learned

What worked

Studying phishing from an infrastructure perspective helped me understand how detection actually happens.

What broke

At first phishing seemed purely social engineering, but in reality there is significant technical analysis involved.

Why it broke

I initially underestimated how much telemetry email systems generate.

Fix / takeaway

Learn how phishing appears in real logs and investigation workflows.


📈 Skill Progression Context

This topic builds on earlier SOC investigation learning.

Understanding phishing detection will help when studying:

  • email gateway logs
  • SIEM alerts
  • suspicious login activity
  • account compromise investigations

These are common incidents handled by SOC analysts.