Phishing
Also known as: Email phishing, Credential phishing, Spear phishing, Business email compromise (related)
A social-engineering attack that uses a convincing but fraudulent message to trick a person into revealing credentials, approving a payment, or running malware.
Watch it in 60 seconds
How it works
Phishing works on people, not software. The attacker sends a message that imitates a trusted sender and creates a reason to act quickly: an account will be closed, an invoice is overdue, a package is held. The goal is to make the target skip the one check that would expose the fraud.
The payload is usually one of three things: a link to a fake login page that captures whatever is typed, an attachment that runs code when opened, or a plain request for the target to do something harmful themselves, such as approve a payment or hand over a one-time passcode.
The disguise relies on details most people never inspect. The display name is free text and can say anything. The real sending domain may be a lookalike that swaps or adds a character, or a lookalike subdomain of an unrelated site. A link's visible text is independent of where it actually points.
Targeted variants raise the hit rate. Spear phishing uses facts about the specific person; business email compromise impersonates an executive or supplier to redirect a payment. These carry no malware at all, which is why controls that only scan attachments miss them.
Walk through it
Target: Northwind Logistics (you are the SOC analyst)
Stage 1: A reported email
A finance clerk forwarded this to the phishing mailbox. It looks like it is from the company's payroll provider and it is pushing hard on urgency. Read it the way an analyst does: ignore the words, check the facts.
Spot it
- From-domain is a lookalike of a known brand (character swap, added word, or unexpected subdomain).
- Display name and actual sending domain disagree.
- Link text points to a different domain than the href destination.
- Urgency or threat framing paired with a request for credentials, payment, or a one-time passcode.
- SPF, DKIM or DMARC fails for a message claiming to be from a domain that publishes those records.
- First-time sender domain for the organisation, newly registered, or seen from a bulk-mail network.
Mail gateway
ts=2026-10-11T09:14:02Z from=no-reply@payroll-northwind-secure.com to=a.clerk@northwind.example spf=fail dkim=none dmarc=fail action=delivered
ts=2026-10-11T09:31:20Z event=user_report mailbox=phishing@northwind.example message_id=48213kqlMicrosoft 365 — lookalike sender with auth failure
EmailEvents
| where SenderMailFromDomain endswith "-secure.com"
| where SPFCheck == "fail" or DMARC == "fail"
| project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, DeliveryActionTune the domain suffix to the lookalike patterns of your own brand.
sigmaSigma — clicked link to newly reported phishing domain
detection:
selection:
EventID: 'url_click'
url|contains: 'payroll-northwind-secure.com'
condition: selection
level: highStop it
Deploy phishing-resistant MFA
FIDO2 or passkeys bind the login to the real site, so a credential typed into a fake page cannot be replayed. This is the single control that defeats credential phishing even when the user is fooled.
Enforce DMARC at p=reject
Publishing SPF and DKIM and then setting DMARC to reject stops attackers from spoofing your own domain outright, which forces them onto lookalikes that are easier to spot and block.
Reduce exposure, then train
Mail-gateway filtering, link rewriting and attachment detonation remove most phishing before a human sees it. Awareness training handles the remainder and is measured by report rate, not just click rate.
DMARC enforcement record (DNS TXT at _dmarc.yourdomain)
Hardened
v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain; adkim=s; aspf=s; pct=100Start at p=none to collect reports, then move to quarantine and finally reject once legitimate senders pass.
- Rewrite and scan links at delivery time, re-checking the destination at click time.
- Flag external senders and first-contact domains with a visible banner.
- Block or sandbox executable and macro-enabled attachments.
- Give users a one-click report button and auto-quarantine copies from every mailbox on report.
- Require out-of-band verification for any payment or payroll change requested by email.
If it already happened
Quarantine the message and purge every delivered copy across all mailboxes. Block the sender and link domains at the mail gateway and web proxy.
Hunt for users who clicked or submitted credentials. Reset affected passwords, revoke active sessions and tokens, and check for inbox rules the attacker may have created.
Confirm accounts are clean, restore any changed payment details through a verified channel, and report the lookalike domain to the provider and registrar for takedown.
Record the lure and indicators, add them to detections, and feed the real-world example into awareness training. Track the report rate, not only the click rate.
Check yourself
1. An email's display name is 'IT Helpdesk' but the From address domain is 'it-helpdesk-support.net', which the company does not own. What is the strongest single conclusion?
2. Which control most directly prevents a phished credential from being reused against your login portal?
3. A user reports a suspicious email with a login link. What should the analyst do with the link?