Phishing and Initial Access: Email, Malicious Attachment, AiTM and MFA Bypass
Incident response playbook for phishing email, malicious attachment/link execution, and AiTM/MFA bypass incidents.
Prepare
6 steps- Reporting channel
A user channel for phishing reporting must be ready (phish button or security email address); mark as missing control if absent.
- Email gateway
URL rewrite (Safe Links) and attachment sandbox detonation must be active; QR code analysis must be enabled.
- Detection rules
Entra ID SigninLogs → SIEM integration must be operational; AiTM indicator (`anomalousToken`) and MFA fatigue (`push bombing`) rules must be in production.
- Authority definition
SOC authority to suspend accounts, execute `Revoke-MgUserSignInSession`, and run Exchange Online Compliance Search must be pre-defined and tested.
- Classification criteria
The P1–P4 threshold for the incident and the 72-hour window for GDPR notification must be documented.
- MFA status
Phishing-resistant MFA (FIDO2/passkey) or at minimum number matching must be enabled organization-wide; push-only MFA is insufficient against AiTM.