Week 3
Investigate a Credential-Phishing Response
Client Background
Northwind Logistics is a regional logistics company. An employee reported a suspicious email that looked like a Microsoft 365 password-expiry alert; several coworkers received the same message and two clicked the link and 'reset' their passwords.
Business Environment
You are the Tier-1 SOC analyst on the Northwind M365 tenant. SIEM ingests Azure AD sign-in logs, Microsoft 365 Defender, and mail-flow logs. The CISO wants a same-day determination of impact and containment.
Security Incident
At 08:14, a phishing email was reported. By 09:30, two users (p.martinez, r.lee) had signed in from a new geo (Lagos, NG) despite being based in Dallas, and one had a new mailbox rule named 'FW' forwarding all mail to an external address.
Scope
Azure AD sign-ins, M365 Defender alerts, mail-flow and mailbox rules for the affected users. Excludes endpoint forensics (no EDR alerts in scope).
Objectives
- Confirm the phishing chain from email to account takeover
- Identify every account that submitted credentials
- Detect attacker persistence and data collection actions
- Document containment and recovery steps
- Recommend phishing-resistant authentication (FIDO2/passkeys) and session-token-binding/revocation as the durable AiTM mitigation, and rename Azure AD references to Microsoft Entra ID.
Required Deliverables