High severityHARDEC6 steps · 5 phases
Phishing & Initial Access Response
Response to initial access incidents originating from phishing / malicious attachments / credential harvesting.
Information note
Informational note: When responding to phishing-sourced initial access, examine email headers, URL redirect chains, and attachment metadata together. Under MITRE ATT&CK TA0001, phishing links (T1566.002) and malicious attachments (T1566.001) produce different detection signals. Against MFA bypass techniques, revoke all affected sessions and enforce re-authentication until Conditional Access policies and phishing-resistant MFA (FIDO2) are deployed.
1
Preparation
1 steps- Phishing reporting channel and auto-analysis
User report-phishing button, mail sandbox, URL detonation, EDR.
2
Detection & Analysis
1 steps- Determine scope
Find all recipients of the same campaign; identify users who clicked or entered credentials.
3
Containment, Eradication & Recovery
2 steps- Cut off access
Purge the malicious message from all mailboxes, block sender/URL/IP, terminate sessions of users who clicked and enforce MFA.
- Clean up side effects
Quarantine payload, remove created inbox rules / OAuth permissions, reset passwords.
4