Phishing Scenario (SIEM + SOAR)

Table Of Content

  1. Overview
  2. Demo Workflow

Overview

This guideline will help you to setup & build an environment to showcase SOAR features

Phishing Scenario

Employee receive a phishing email, he opens and click on the word attachment file

Demo Workflow

Pasted image 20240715104709.png

Components

Phishing Attack Setup

Install & Setup Gophish

Download & Setup using this link
Email Phishing Template: Starbucks Phishing Email Template

Install & Setup Microsoft Exchange 2019

Using this link

Important

Following this Exchange 2019 onprem to grant SOAR Service Account privileges to scan others mailbox folder.

Qradar SIEM Setup

In this detection phrase, I will create 2 rules to detect phishing attack:

  1. Detect suspicious phishing subject with attachment file.
  2. Detect anomalous traffic to the machine which previously received/opened suspicious phishing email.

Resilient Setup

SOAR will be important components for incident response to phishing attack by leveraging orchestrating security product and collaboration teams, to setup SOAR, complete the following tasks:

Demo Video