WHAT YOU WILL LEARN
Learning objectives
- Distinguish credential theft, consent phishing and BEC
- Preserve evidence for an investigation
- Choose remediation that matches the access gained
Classify the requested action
A business email compromise may ask for a payment change without using malware. A fake sign-in page seeks credentials or codes. Consent phishing asks the user to authorise an application. These cases require different evidence and containment. A familiar sender can be a compromised account, so examine the request and business process as well as the address.
Build the evidence picture
Preserve the original message and relevant timestamps using approved tooling. Review sign-ins, forwarding rules, consent grants and affected transactions within your authority. Keep sensitive evidence in approved storage. Avoid clicking malicious links to “see what happens” from a normal work device.
Close the actual access path
Contain affected accounts and sessions, review mailbox rules and application permissions, and coordinate payment verification with finance. Email authentication such as SPF, DKIM and DMARC helps address specific forms of domain abuse; it does not prevent every deceptive request from a legitimate compromised mailbox.
Improve the process
Use the investigation to improve approval and reporting steps. Train users with realistic examples and constructive feedback. The target is a reliable verification habit, not a claim that every person can identify every malicious message.
APPLIED EXAMPLE
Put it in context
A fictional supplier mailbox is compromised and sends a plausible bank-detail change. The customer’s independent callback process stops the transfer even though the email comes from a real account.
Illustrative scenario for learning, not a claim about a verified customer incident.Common mistakes
- Relying only on spelling mistakes
- Assuming DMARC prevents all BEC
- Ignoring forwarding rules and app grants
Your practical checklist
Checklist ticks are temporary and are not recorded as account progress.
MINI RECAP
Effective phishing defense joins technical investigation with business verification and proportionate account remediation.
Put your understanding to the test.
Go further in the SOC Analyst Track
The free base is available now. Applied labs, assessed evidence and authenticated history are planned extensions.
Explore the learning track →