📅 Day 53 — Understanding Phishing Attacks and Email Security Layers
🎯 Goal
The goal for today was to deepen my understanding of phishing attacks, which remain one of the most common initial access techniques used by attackers.
Instead of focusing only on the social engineering aspect, I explored:
- how phishing campaigns work technically
- how organizations detect them
- what telemetry defenders use to investigate them
This is important because phishing frequently leads to:
- credential theft
- malware infection
- account compromise
- initial access into corporate environments
🛠 What I Did
Today I studied the mechanics behind phishing attacks and how companies defend against them.
Key topics explored:
- how phishing emails trick users
- email infrastructure used in attacks
- security controls designed to detect spoofed emails
Phishing is fundamentally a social engineering attack where the attacker impersonates something trusted.
Common examples include attackers pretending to be:
- a bank
- Microsoft or Google
- Amazon
- a company IT department
- a manager or executive
The attacker then attempts to convince the victim to:
- click a malicious link
- download a malicious attachment
- reveal credentials or sensitive data
🔗 Key Cybersecurity Connections
Phishing is often the first stage of larger attacks.
A typical attack chain might look like:
Phishing email
↓
Victim enters credentials on fake page
↓
Attacker gains account access
↓
Attacker logs into company systems
↓
Lateral movement begins
Because of this, detecting phishing attempts early is critical.
🔍 Investigation Questions
If a phishing alert appeared in security telemetry, a SOC analyst might ask:
- What email address and domain sent the message?
- Did the email pass SPF, DKIM, and DMARC authentication checks?
- Is the sender domain newly registered or suspiciously similar to a legitimate domain?
- Did multiple employees receive the same email?
- Did any users click the link or download attachments?
- Were credentials entered on a suspicious webpage following the email?
These questions help analysts determine whether the message is part of a larger phishing campaign or targeted attack.
🚨 Detection Opportunities
Possible detection strategies for phishing attacks include:
- monitoring SPF, DKIM, and DMARC failures
- detecting look-alike or newly registered domains
- correlating URLs with threat intelligence feeds
- alerting when multiple employees receive similar suspicious emails
- monitoring authentication logs for login attempts following phishing emails
Telemetry sources commonly used include:
- email gateway logs
- DNS logs
- proxy logs
- authentication logs
- endpoint browser telemetry.
🧭 MITRE ATT&CK Techniques
Phishing attacks are associated with several MITRE ATT&CK techniques:
- T1566 – Phishing
- T1566.001 – Spearphishing Attachment
- T1566.002 – Spearphishing Link
- T1204 – User Execution
These techniques describe how attackers trick users into executing malicious actions that lead to initial compromise.
📡 Email Security Layers
Organizations use several defensive layers to detect phishing.
Email Security Gateways
Examples include:
- Proofpoint
- Mimecast
- Microsoft Defender for Office 365
These systems scan incoming emails for:
- malicious links
- suspicious attachments
- spoofed senders
- known malicious domains
Domain Authentication Technologies
Three important mechanisms help detect spoofed email senders:
SPF (Sender Policy Framework)
Defines which mail servers are allowed to send email for a domain.
DKIM (DomainKeys Identified Mail)
Adds a cryptographic signature to verify the message integrity.
DMARC (Domain-based Message Authentication, Reporting & Conformance)
Combines SPF and DKIM to define how receiving servers handle failures.
These technologies help prevent attackers from impersonating legitimate domains.
⚠ Challenges
The most challenging part was understanding that phishing detection is not just about spotting suspicious emails manually.
In real organizations, detection relies on:
- automated filtering systems
- reputation databases
- authentication failures
- behavioral analysis
Investigating phishing often requires analyzing multiple log sources.
📚 What I Learned
Key takeaways:
- phishing remains one of the most effective attack methods
- attackers rely on trust and urgency
- technical defenses rely heavily on email authentication and filtering
Understanding phishing from both perspectives helps analysts:
- detect malicious campaigns
- investigate suspicious emails
- prevent credential theft.
➡ Next Steps
Next I want to explore:
- how phishing emails appear in security logs
- how SOC analysts investigate suspicious email events
- how malicious domains are detected
🧠 Reflection
Phishing is a reminder that cybersecurity is not only technical — it also involves human psychology.
Even highly secure systems can be compromised if a user is tricked into giving access.
This reinforces the importance of combining:
- technical defenses
- monitoring
- user awareness training.
🧩 Lessons Learned
What worked
Studying phishing from an infrastructure perspective helped me understand how detection actually happens.
What broke
At first phishing seemed purely social engineering, but in reality there is significant technical analysis involved.
Why it broke
I initially underestimated how much telemetry email systems generate.
Fix / takeaway
Learn how phishing appears in real logs and investigation workflows.
📈 Skill Progression Context
This topic builds on earlier SOC investigation learning.
Understanding phishing detection will help when studying:
- email gateway logs
- SIEM alerts
- suspicious login activity
- account compromise investigations
These are common incidents handled by SOC analysts.
