Phishing Incident Playbook başlıklı kaynağın profesyonel teknik özetidir. Aşağıda belgenin ana başlık ve içerik yapısı Türkçe açıklamalarla sunulmuştur.
PHISHING RUNBOOK/PLAYBOOK Phishing playbook guides SOC teams in detecting, analyzing, and responding to phishing threats. SOC phishing detection and response guide. Defines roles, triage, and investigation steps. Focuses on email, credential, and social engineering threats. Ensures quick containment and awareness. Promotes continuous improvement and prevention. Kumar Bineet Ranjan Contents 1. Introduction & Objective ......................................................................................................... 4 2. Roles & Responsibilities ....................................
........................................................................ 5 3. Phishing Taxonomy — Full Details (16 Variants) .................................................................. 7 3.1 Email Phishing (Mass / Spray) .......................................................................................... 7 3.2 Spear Phishing (Targeted) ................................................................................................. 9 3.3 Whaling (Executive-targeted).......................................................................................... 10 3.4 Business Email Comp...
romise (BEC) ............................................................................... 11 3.5 Smishing (SMS) .............................................................................................................. 12 3.6 Vishing (Voice) ............................................................................................................... 13 3.7 QRishing (QR Code Phishing) ........................................................................................ 13 3.8 Pharming (DNS Poisoning) ......................................................................................
.......... 14 3.9 Clone Phishing................................................................................................................. 15 3.10 Watering Hole / Drive-by .............................................................................................. 15 3.11 Malicious Attachments (Macro/Executable) ................................................................. 16 3.12 Credential Harvesting (Web-form Phishing) ................................................................. 16 3.13 Hybrid (Multi-channel) & 3.14 Angler (Social Media).......................................
............. 17 3.15 Registrar/DNS Compromise (Pharming variant) .......................................................... 17 3.16 Cross-type Meta-signals ................................................................................................ 17 4. Email Authentication Deep Dive (SPF / DKIM / DMARC / ARC) ...................................... 18 1) Mail transfer & where authentication happens (SMTP walkthrough) .............................. 18 2) SPF — deep mechanics & evaluation ............................................................................... 18 3) DKIM — deep mech...
anics, canonicalization & verification ............................................. 20 4) DMARC — deep mechanics & reporting ......................................................................... 21 5) ARC — how it preserves authentication through forwarding ........................................... 22 6) Why authentication checks can be inconclusive (and how attackers abuse that) .............. 23 7) How to check & validate authentication as an analyst (practical steps & commands) ..... 24 8) Recommended org-side settings & best practices (practical configuration guidance) ...... 25 SPF...
........................................................................................................................................ 25 DKIM .................................................................................................................................... 25 DMARC ................................................................................................................................ 25 ARC / Forwarders.................................................................................................................. 25 9) Examples — annotated headers & sample outpu...
ts ........................................................... 25 Example 1 — Spoofed email header (interpreted) ................................................................ 25 Example 2 — DKIM pass, SPF fail, DMARC pass (delegated signing) .............................. 25 Example 3 — ARC chain present ......................................................................................... 26 10) Attacker checklist — how they exploit each mechanism ................................................ 26 11) SOC detection & playbook changes informed by these internals ...........................
........... 26 12) Recommended configuration snippets (for defenders) ................................................... 27 13) Final: FAQ & common analyst pitfalls ........................................................................... 27 5. Detection & Triage — Step-by-step (Analyst Playbook) — expanded ................................ 28 Phase: Intake (0–5 minutes) .................................................................................................. 28 Phase: Preserve (0–10 minutes) ..............................................................................................
.. 28 Phase: Quick Authentication & Header checks (0–15 minutes) ........................................... 29 Phase: Classification & Escalation ........................................................................................ 30 Example ticket template (copyable) ...................................................................................... 31 6. Investigation & Analysis — Static & Dynamic (deep detail) ............................................... 31 Static Analysis — step-by-step ................................................................................................
31 Dynamic Analysis (Sandbox) — step-by-step ...................................................................... 32 IOC Extraction ...................................................................................................................... 33 Examples of suspicious behaviors to look for ....................................................................... 33 Evidence packaging ............................................................................................................... 33 7. Hunting & Correlation (SIEM Queries and Playbooks) — detailed usage .....................
......... 34 Splunk examples — explanations & tuning .......................................................................... 34 Sentinel KQL examples — explanation ................................................................................ 34 Scheduled hunts ..................................................................................................................... 35 IOC enrichment — tools & order .......................................................................................... 35 Playbook (operational steps) .............................................................
Belge toplam 15 paragraf içermektedir; tam metin /root/pdf klasöründeki kaynak dosyasında mevcuttur.