📅 Day 62 — Understanding Phishing Attacks and Email Security Controls
🎯 Goal
Today I focused on understanding phishing attacks, one of the most common entry points for security incidents.
The objective was to explore:
• how phishing campaigns work
• how attackers impersonate trusted services
• how organizations defend against email-based attacks
🛠What I Did
Studied the Structure of Phishing Attacks
Phishing attacks typically rely on social engineering rather than technical exploits.
Instead of hacking a machine directly, attackers trick a user into performing an action.
Common phishing goals include:
• credential theft
• malware delivery
• account takeover
• financial fraud
Examined Email Indicators
Security teams analyze multiple indicators when investigating suspicious emails.
Important fields include:
• sender domain
• email headers
• embedded URLs
• attachments
Investigators also review authentication results from security mechanisms like SPF and DKIM.
Explored Email Security Technologies
Modern email security relies on several protective layers.
SPF (Sender Policy Framework)
Allows a domain to declare which servers are allowed to send email on its behalf.
DKIM (DomainKeys Identified Mail)
Adds cryptographic signatures to emails so recipients can verify authenticity.
DMARC (Domain-based Message Authentication, Reporting and Conformance)
Builds on SPF and DKIM to enforce domain authentication policies.
Together these technologies help detect spoofed messages.
🔗 Key Cybersecurity Connections
Phishing remains one of the most common initial access techniques used by attackers.
Many large breaches begin with:
User receives phishing email
↓
User clicks link or opens attachment
↓
Credentials or malware delivered
↓
Attacker gains foothold
Because of this, SOC teams often investigate suspicious emails daily.
âš Challenges
One challenge is that phishing campaigns often mimic legitimate communication very convincingly.
Attackers may:
• copy real branding
• use compromised accounts
• register similar domains (typosquatting)
This makes detection harder for both users and automated systems.
📚 What I Learned
Key lessons:
• phishing targets human trust rather than technical vulnerabilities
• email authentication protocols help detect spoofed messages
• security awareness is a critical defensive layer
âž¡ Next Steps
Future exploration:
• analyzing phishing email headers
• examining malicious attachments in sandbox environments
• studying real phishing campaigns
🧠Reflection
Even with advanced security technology, human behavior remains one of the most difficult attack surfaces to secure.
Phishing demonstrates how attackers combine psychology with technical infrastructure.
Understanding both sides is essential for defenders.
🧩 Lessons Learned
What worked
Breaking down email authentication protocols clarified how modern email defenses function.
What broke
It is easy to assume phishing attacks are obvious.
Why it broke
Modern campaigns are highly sophisticated.
Fix / takeaway
Investigations should always examine both technical indicators and user context.
🔎 Investigation Questions
• How can SOC teams quickly identify malicious domains in phishing campaigns?
• What indicators help differentiate spoofed emails from legitimate ones?
• How do attackers bypass email security controls?
🛡 Detection Opportunities
Potential detections include:
• suspicious login attempts after phishing emails
• email authentication failures (SPF / DKIM / DMARC)
• abnormal outbound email patterns
🎯 MITRE ATT&CK Techniques
Relevant techniques include:
T1566 — Phishing
T1566.001 — Spearphishing Attachment
T1566.002 — Spearphishing Link
🧠Investigation Flow
Phishing Email
↓
User Interaction
↓
Credential Theft or Malware Execution
↓
Initial Access
↓
SOC Investigation
📈 Skill Progression Context
Understanding phishing improves my ability to recognize initial access vectors, one of the most common tasks for SOC analysts investigating alerts and incidents.
