Reveal, timeline, and report, phishing and BEC email investigation exercises for SOC analysts
Dana Whitfield, an accounts-payable clerk at the fictional Cascade Logistics, forwards a 'past-due invoice' email to the SOC after her workstation starts running hot and sluggish. Determine whether the email is malicious, how any payload would have executed, and which indicators should be blocked.
A shared Accounts Payable mailbox flags a remittance-advice email as suspicious the moment SPF shows 'fail.' Before this becomes a blocked vendor, work out whether the mail path itself explains the failure.
A wire-transfer bank-details change request to the CFO passes SPF, DKIM, and DMARC cleanly. Work out why a fully authenticated message can still be a forgery, and what actually proves it.
A user reports clicking a link in a credential-harvest-styled email before reporting it, three days later. The headers and a sandbox detonation establish the email itself was phishing, but not what happened on her screen. Work out exactly what this evidence can and cannot prove, and what would close the gap.