← Sızma Testi & Kırmızı Takım

Phishing Incident Playbook

Kategori: Sızma Testi & Kırmızı Takım · Sayfa: 49

Phishing Incident Playbook başlıklı kaynağın profesyonel teknik özetidir. Aşağıda belgenin ana başlık ve içerik yapısı Türkçe açıklamalarla sunulmuştur.

PHISHING RUNBOOK/PLAYBOOK Phishing playbook guides SOC teams in detecting, analyzing, and responding to phishing threats.  SOC phishing detection and response guide.  Defines roles, triage, and investigation steps.  Focuses on email, credential, and social engineering threats.  Ensures quick containment and awareness.  Promotes continuous improvement and prevention. Kumar Bineet Ranjan Contents 1. Introduction & Objective ......................................................................................................... 4 2. Roles & Responsibilities ....................................

........................................................................ 5 3. Phishing Taxonomy — Full Details (16 Variants) .................................................................. 7 3.1 Email Phishing (Mass / Spray) .......................................................................................... 7 3.2 Spear Phishing (Targeted) ................................................................................................. 9 3.3 Whaling (Executive-targeted).......................................................................................... 10 3.4 Business Email Comp...

romise (BEC) ............................................................................... 11 3.5 Smishing (SMS) .............................................................................................................. 12 3.6 Vishing (Voice) ............................................................................................................... 13 3.7 QRishing (QR Code Phishing) ........................................................................................ 13 3.8 Pharming (DNS Poisoning) ......................................................................................

.......... 14 3.9 Clone Phishing................................................................................................................. 15 3.10 Watering Hole / Drive-by .............................................................................................. 15 3.11 Malicious Attachments (Macro/Executable) ................................................................. 16 3.12 Credential Harvesting (Web-form Phishing) ................................................................. 16 3.13 Hybrid (Multi-channel) & 3.14 Angler (Social Media).......................................

............. 17 3.15 Registrar/DNS Compromise (Pharming variant) .......................................................... 17 3.16 Cross-type Meta-signals ................................................................................................ 17 4. Email Authentication Deep Dive (SPF / DKIM / DMARC / ARC) ...................................... 18 1) Mail transfer & where authentication happens (SMTP walkthrough) .............................. 18 2) SPF — deep mechanics & evaluation ............................................................................... 18 3) DKIM — deep mech...

anics, canonicalization & verification ............................................. 20 4) DMARC — deep mechanics & reporting ......................................................................... 21 5) ARC — how it preserves authentication through forwarding ........................................... 22 6) Why authentication checks can be inconclusive (and how attackers abuse that) .............. 23 7) How to check & validate authentication as an analyst (practical steps & commands) ..... 24 8) Recommended org-side settings & best practices (practical configuration guidance) ...... 25 SPF...

........................................................................................................................................ 25 DKIM .................................................................................................................................... 25 DMARC ................................................................................................................................ 25 ARC / Forwarders.................................................................................................................. 25 9) Examples — annotated headers & sample outpu...

ts ........................................................... 25 Example 1 — Spoofed email header (interpreted) ................................................................ 25 Example 2 — DKIM pass, SPF fail, DMARC pass (delegated signing) .............................. 25 Example 3 — ARC chain present ......................................................................................... 26 10) Attacker checklist — how they exploit each mechanism ................................................ 26 11) SOC detection & playbook changes informed by these internals ...........................

........... 26 12) Recommended configuration snippets (for defenders) ................................................... 27 13) Final: FAQ & common analyst pitfalls ........................................................................... 27 5. Detection & Triage — Step-by-step (Analyst Playbook) — expanded ................................ 28 Phase: Intake (0–5 minutes) .................................................................................................. 28 Phase: Preserve (0–10 minutes) ..............................................................................................

.. 28 Phase: Quick Authentication & Header checks (0–15 minutes) ........................................... 29 Phase: Classification & Escalation ........................................................................................ 30 Example ticket template (copyable) ...................................................................................... 31 6. Investigation & Analysis — Static & Dynamic (deep detail) ............................................... 31 Static Analysis — step-by-step ................................................................................................

31 Dynamic Analysis (Sandbox) — step-by-step ...................................................................... 32 IOC Extraction ...................................................................................................................... 33 Examples of suspicious behaviors to look for ....................................................................... 33 Evidence packaging ............................................................................................................... 33 7. Hunting & Correlation (SIEM Queries and Playbooks) — detailed usage .....................

......... 34 Splunk examples — explanations & tuning .......................................................................... 34 Sentinel KQL examples — explanation ................................................................................ 34 Scheduled hunts ..................................................................................................................... 35 IOC enrichment — tools & order .......................................................................................... 35 Playbook (operational steps) .............................................................

Belge toplam 15 paragraf içermektedir; tam metin /root/pdf klasöründeki kaynak dosyasında mevcuttur.

← Kategoriye dön