Phishing Unfolding SIM (SOC Simulator TryHackMe)
Dive into the heat of a live phishing attack as it unfolds within the corporate network. In this high-pressure scenario, your role is to meticulously analyze and document each phase of the breach as it happens.
- First I let all the alert to come to correlate them together.
- You start from the CRITICAL ones (0 alert) - HIGH - MEDIUM - LOW.
- I check all dns alert , all of them was false positive , nothing suspicious .
- On the Process ones you must to check on splunk , search on google if you don't know the specific process .
I make one mistake , with the attashments invoice.pdf.ink , apparently it was true positive , but I check the SHA-256 on VirusTotal , nothing suspicious..
I realy enjoy with this SIM , Have Fun !!

Comments
Post a Comment