Back to category

Week 3

Investigate a Credential-Phishing Response

Beginner
SOC Analyst
Incident Responder
Cybersecurity Analyst
MITRE ATT&CK
NIST CSF
NIST 800-61
NIST CSF 2.0
Phishing Analysis
Azure AD Log Analysis
Mailbox Rule Abuse
Account Takeover Response
Microsoft Entra ID Log Analysis
Phishing-Resistant MFA

Client Background

Northwind Logistics is a regional logistics company. An employee reported a suspicious email that looked like a Microsoft 365 password-expiry alert; several coworkers received the same message and two clicked the link and 'reset' their passwords.

Business Environment

You are the Tier-1 SOC analyst on the Northwind M365 tenant. SIEM ingests Azure AD sign-in logs, Microsoft 365 Defender, and mail-flow logs. The CISO wants a same-day determination of impact and containment.

Security Incident

At 08:14, a phishing email was reported. By 09:30, two users (p.martinez, r.lee) had signed in from a new geo (Lagos, NG) despite being based in Dallas, and one had a new mailbox rule named 'FW' forwarding all mail to an external address.

Scope

Azure AD sign-ins, M365 Defender alerts, mail-flow and mailbox rules for the affected users. Excludes endpoint forensics (no EDR alerts in scope).

Objectives

  • Confirm the phishing chain from email to account takeover
  • Identify every account that submitted credentials
  • Detect attacker persistence and data collection actions
  • Document containment and recovery steps
  • Recommend phishing-resistant authentication (FIDO2/passkeys) and session-token-binding/revocation as the durable AiTM mitigation, and rename Azure AD references to Microsoft Entra ID.

Required Deliverables

Incident Summary
Containment Checklist
3 hrs estimated