Phishing Unfolding SIM (SOC Simulator TryHackMe)


 

      Dive into the heat of a live phishing attack as it unfolds within the corporate network. In this high-pressure scenario, your role is to meticulously analyze and document each phase of the breach as it happens.







  • First I let all the alert to come to correlate them together.
  • You start from the CRITICAL ones (0 alert) - HIGH - MEDIUM - LOW.
  • I check all dns alert , all of them was false positive , nothing suspicious .
  • On the Process ones you must to check on splunk , search on google if you don't know the specific process .

I make one mistake , with the attashments invoice.pdf.ink , apparently it was true positive , but I check the SHA-256 on VirusTotal , nothing suspicious.. 



I realy enjoy with this SIM , Have Fun !! 


Comments

Popular posts from this blog

TryHackMe - Threat Hunting Simulator - Health Hazard

TryHackMe - Typo Snare Threat Hunter Simulator (medium level)