This is the final video on phishing before we start heading into malware analysis. PLEASE excuse any errors that may exist with the sped up portions. In this video we put all the things we learned from Volume 1 ( • Day in the life of a SOC Analyst - Analyzi... ) and 2 ( • Day in the life of a SOC analyst - Analyzi... ) together and show you how to do some of the following:
NOTE: the phishing report / document contains more details and some corrected portions.
Investigate (with powershell) AD users, roles, password expiration and lockout(s)
Obtain object hashes in windows with certutil
Investigate with whois, nslookup and ping.
Avoid clicking on links which can help identify if a user is active, ensnare those users in phishing campaigns or show that a user "clicked" when it was the analyst who did!
Use recipient threat intel with https://haveibeenpwned.com to see if a user is in recent breaches and compare that to password dates/times.
Leveraging threat intel from sources like IBM X-Force and searching (splunk) our SIEM for indicators that may not have been detected.
Using google to search for threat actor e-mail (we will go more in depth with OSINT in later videos)
Use open source intelligence like VirusTotal to identify what may have leaked at your organization
Identify if the e-mail received is a phishing test or a threat actor
Identify phishing ramping phase(s)
Exploring the custom tools I've written for phishing and e-mail analysis
Explore a writeup of a phishing analysis.
Tools discussed:
splunk
thunderbird, outlook
whois
nslookup
ping
Threat Intelligence:
https://google.com
https://virustotal.com
https://exchange.xforce.ibmcloud.com/
https://whatsmyname.app (can be used for threat actor)
https://mxtoolbox.com - IP reputation
https://ipvoid.com - IP reputation
https://archive.org - Dead Domains / way back machine.
Supporting Documents / Tools (Google Drive):
Full report: https://drive.google.com/file/d/1HJ2o... (PDF)
E-Mail Investigation Tool: https://drive.google.com/file/d/1CqLz...
Phishing Domain Tool: Coming soon!
#dfir #phishinganalysis #incidentresponse #socanalyst #soc #informationsecurity #cybersecurity #lessonslearned #terminal #outlook #businessemailcompromise #bec