🎯 Goal

Today I focused on understanding phishing attacks, one of the most common entry points for security incidents.

The objective was to explore:

• how phishing campaigns work
• how attackers impersonate trusted services
• how organizations defend against email-based attacks


🛠 What I Did

Studied the Structure of Phishing Attacks

Phishing attacks typically rely on social engineering rather than technical exploits.

Instead of hacking a machine directly, attackers trick a user into performing an action.

Common phishing goals include:

• credential theft
• malware delivery
• account takeover
• financial fraud


Examined Email Indicators

Security teams analyze multiple indicators when investigating suspicious emails.

Important fields include:

• sender domain
• email headers
• embedded URLs
• attachments

Investigators also review authentication results from security mechanisms like SPF and DKIM.


Explored Email Security Technologies

Modern email security relies on several protective layers.

SPF (Sender Policy Framework)

Allows a domain to declare which servers are allowed to send email on its behalf.

DKIM (DomainKeys Identified Mail)

Adds cryptographic signatures to emails so recipients can verify authenticity.

DMARC (Domain-based Message Authentication, Reporting and Conformance)

Builds on SPF and DKIM to enforce domain authentication policies.

Together these technologies help detect spoofed messages.


🔗 Key Cybersecurity Connections

Phishing remains one of the most common initial access techniques used by attackers.

Many large breaches begin with:

User receives phishing email
↓
User clicks link or opens attachment
↓
Credentials or malware delivered
↓
Attacker gains foothold

Because of this, SOC teams often investigate suspicious emails daily.


âš  Challenges

One challenge is that phishing campaigns often mimic legitimate communication very convincingly.

Attackers may:

• copy real branding
• use compromised accounts
• register similar domains (typosquatting)

This makes detection harder for both users and automated systems.


📚 What I Learned

Key lessons:

• phishing targets human trust rather than technical vulnerabilities
• email authentication protocols help detect spoofed messages
• security awareness is a critical defensive layer


âž¡ Next Steps

Future exploration:

• analyzing phishing email headers
• examining malicious attachments in sandbox environments
• studying real phishing campaigns


🧠 Reflection

Even with advanced security technology, human behavior remains one of the most difficult attack surfaces to secure.

Phishing demonstrates how attackers combine psychology with technical infrastructure.

Understanding both sides is essential for defenders.


🧩 Lessons Learned

What worked
Breaking down email authentication protocols clarified how modern email defenses function.

What broke
It is easy to assume phishing attacks are obvious.

Why it broke
Modern campaigns are highly sophisticated.

Fix / takeaway
Investigations should always examine both technical indicators and user context.


🔎 Investigation Questions

• How can SOC teams quickly identify malicious domains in phishing campaigns?
• What indicators help differentiate spoofed emails from legitimate ones?
• How do attackers bypass email security controls?


🛡 Detection Opportunities

Potential detections include:

• suspicious login attempts after phishing emails
• email authentication failures (SPF / DKIM / DMARC)
• abnormal outbound email patterns


🎯 MITRE ATT&CK Techniques

Relevant techniques include:

T1566 — Phishing
T1566.001 — Spearphishing Attachment
T1566.002 — Spearphishing Link


🧭 Investigation Flow

Phishing Email
↓
User Interaction
↓
Credential Theft or Malware Execution
↓
Initial Access
↓
SOC Investigation


📈 Skill Progression Context

Understanding phishing improves my ability to recognize initial access vectors, one of the most common tasks for SOC analysts investigating alerts and incidents.