Phishing Incident v3
Phishing Incident
Details
| ID | Phishing Incident v3 |
|---|---|
| Group | incident |
| Version | -1 |
| From Version | 6.1.0 |
Layout Structure
Classic Summary 0 sections
No sections defined.
Case info 14 sections
Email Attachments
| Field ID | Position |
|---|---|
| attachment | Col 0-2, Height: 53 |
Case Basic Details
| Field ID | Position |
|---|---|
| occurred | Col 0-2, Height: 22 |
| severity | Col 0-2, Height: 22 |
| owner | Col 0-2, Height: 22 |
| reportedemailorigin | Col 0-2, Height: 22 |
| reportedemailfrom | Col 0-2, Height: 22 |
| reportedemailto | Col 0-2, Height: 22 |
| reportedemailcc | Col 0-2, Height: 22 |
| reporteremailaddress | Col 0-2, Height: 22 |
| emailbcc | Col 0-2, Height: 22 |
| reportedemailsubject | Col 0-2, Height: 22 |
| attachmentcount | Col 0-2, Height: 22 |
| emailrecipientscount | Col 0-2, Height: 22 |
| additionalemailaddresses | Col 0-2, Height: 26 |
| categories | Col 0-2, Height: 22 |
Incident Files
Indicators
Email HTML Image
URL Screenshots
Related Phishing Campaign
Work Plan
Response action
| Field ID | Position |
|---|---|
| reportedemailto | Col 0-2, Height: 22 |
| reportedemailmessageid | Col 0-2, Height: 22 |
| emaildeletetype | Col 0-2, Height: 22 |
| emaildeletefrombrand | Col 0-2, Height: 22 |
| — | Col 0-2, Height: 44 |
Email Delete Result
| Field ID | Position |
|---|---|
| emaildeleteresult | Col 0-2, Height: 22 |
| emaildeletereason | Col 0-2, Height: 22 |
Linked Incidents
Selected indicators to block
Indicators selected to be blocked.
Email Body
:warning: This section contains the original HTML of the email. Links may lead to malicious websites!
Incident SLAs
| Field ID | Position |
|---|---|
| triagesla | Col 0-2, Height: 53 |
| remediationsla | Col 0-2, Height: 53 |
| detectionsla | Col 1-2, Height: 53 |
Investigation 10 sections
Email Headers
Headers extracted from the original email.
| Field ID | Position |
|---|---|
| emailheaders | Col 0-4, Height: 106 |
Headers Analysis
Analysis of SPF, DKIM, DMARC and Microsoft anti-spam headers. For Microsoft anti-spam headers, please click on each item for the relevant documentation: [PCL](https://docs.microsoft.com/en-us/exchange/antispam-and-antimalware/antispam-protection/antispam-stamps?view=exchserver-2019) - Phishing Confidence Level. [BCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/bulk-complaint-level-values?view=o365-worldwide) - Bulk Complaint Level. [SCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels?view=o365-worldwide) - Spam Confidence Level. `Note`: The default value is 0, but it can be changed when the "Process Microsoft's Email Headers" playbook runs.
| Field ID | Position |
|---|---|
| emailauthenticitycheck | Col 0-1, Height: 53 |
| phishingbclscore | Col 0-1, Height: 53 |
| phishingsclscore | Col 1-2, Height: 53 |
| phishingpclscore | Col 1-2, Height: 53 |
ML Prediction For The Email
Results of machine-learning checks on the email using a pretrained model.
| Field ID | Position |
|---|---|
| dbotpredictionprobability | Col 0-1, Height: 53 |
| dbotprediction | Col 0-1, Height: 53 |
| dbottextsuggestionhighlighted | Col 0-2, Height: 106 |
Email Type Information
The category of the email. In case of a phishing email, also shows the phishing sub-type.
| Field ID | Position |
|---|---|
| emailclassification | Col 0-2, Height: 22 |
| phishingsubtype | Col 2-4, Height: 22 |
Raw Email HTML
| Field ID | Position |
|---|---|
| emailhtml | Col 0-4, Height: 44 |
Spear Phishing Investigation
| Field ID | Position |
|---|---|
| emailkeywordsfound | Col 0-2, Height: 22 |
| domainsquattingresult | Col 0-2, Height: 44 |
ML Prediction for URLs
Provides machine-learning based detection of phishing URLs (shows only malicious detections).
Macro Source Code
In case a macro code was found in any of the attachments, the source code will appear here.
| Field ID | Position |
|---|---|
| macrosourcecode | Col 0-2, Height: 22 |
Malicious Clicked URLs information
In case there were URLs in the email with a score of 3 or above which the user clicked for the email investigated in this incident, they will appear in the **Clicked URLs** table. **Total Malicious URLs Clicks** represents the number of clicks in all emails (other emails as well) associated with any of the malicious URLs found in this email. **Malicious URL Viewed** will be **True** if the click was allowed or the user clicked through, in case it was blocked.
| Field ID | Position |
|---|---|
| maliciousurlclicked | Col 0-1, Height: 53 |
| clickedurls | Col 0-4, Height: 106 |
| maliciousurlviewed | Col 1-2, Height: 53 |
| totalmaliciousurlsclicks | Col 2-3, Height: 53 |
Threat Intelligence Analysis
| Field ID | Position |
|---|---|
| relatedcampaign | Col 0-2, Height: 22 |
| relatedreport | Col 0-2, Height: 22 |
War Room 0 sections
No sections defined.
Work Plan 0 sections
No sections defined.
Evidence Board 0 sections
No sections defined.
Related Incidents 0 sections
No sections defined.
Canvas 0 sections
No sections defined.
{ "detailsV2": { "tabs": [ { "hidden": false, "id": "summary", "name": "Classic Summary", "type": "summary" }, { "hidden": false, "id": "swtuqptgvs", "name": "Case info", "sections": [ { "displayType": "CARD", "h": 2, "hideItemTitleOnlyOne": true, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-57f33cc0-97ee-11e9-b8bd-0b00be54d2d3", "isVisible": true, "items": [ { "dropEffect": "move", "endCol": 2, "fieldId": "attachment", "height": 53, "id": "9cd0f990-ac6b-11e9-bb03-dd1b065c10a8", "index": 0, "listId": "swtuqptgvs-49052550-97f0-11e9-b8bd-0b00be54d2d3", "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Email Attachments", "static": false, "w": 1, "x": 2, "y": 3 }, { "displayType": "ROW", "h": 3, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3", "isVisible": true, "items": [ { "endCol": 2, "fieldId": "occurred", "height": 22, "id": "418772e0-a901-11ec-8585-0dac7af6e9b0", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "severity", "height": 22, "id": "45ef12c0-a901-11ec-8585-0dac7af6e9b0", "index": 1, "listId": "swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "owner", "height": 22, "id": "4b1ac5f0-a901-11ec-8585-0dac7af6e9b0", "index": 2, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "reportedemailorigin", "height": 22, "id": "b8f3e800-6279-11ec-8fa2-217b8b611613", "index": 3, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "reportedemailfrom", "height": 22, "id": "be942ef0-6279-11ec-8fa2-217b8b611613", "index": 4, "listId": "swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "reportedemailto", "height": 22, "id": "c2ce0810-6279-11ec-8fa2-217b8b611613", "index": 5, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "reportedemailcc", "height": 22, "id": "b6f8e8b0-a901-11ec-8585-0dac7af6e9b0", "index": 6, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "reporteremailaddress", "height": 22, "id": "93c5bbb0-df83-11e9-9d3d-b355b2831118", "index": 7, "listId": "swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "emailbcc", "height": 22, "id": "2bd969b0-879c-11ed-b4ee-6db51deb2f6e", "index": 8, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "reportedemailsubject", "height": 22, "id": "02f6f6c0-111c-11ee-a4d9-8dbe5c55933f", "index": 9, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "attachmentcount", "height": 22, "id": "86ae8b10-a901-11ec-8585-0dac7af6e9b0", "index": 10, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "emailrecipientscount", "height": 22, "id": "77a63970-6279-11ec-8fa2-217b8b611613", "index": 11, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "additionalemailaddresses", "height": 26, "id": "c477b540-d63e-11ee-a660-f13ca793ceb6", "index": 11, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "categories", "height": 22, "id": "5e2287d0-e502-11ed-ba0f-99a713ead7dc", "index": 12, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Case Basic Details", "static": false, "w": 1, "x": 0, "y": 0 }, { "displayType": "ROW", "h": 2, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-067d4900-98b4-11e9-97d7-ed26ef9e46c8", "isVisible": true, "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Incident Files", "query": { "categories": [ "attachments" ], "notTags": [ "email_html_image", "url_screenshots" ], "tags": [], "tagsAndOperator": true }, "queryType": "warRoomFilter", "readOnly": true, "static": false, "type": "invTimeline", "w": 2, "x": 0, "y": 14 }, { "displayType": "ROW", "h": 5, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-cc557320-98b7-11e9-b34a-852d068f44fe", "isVisible": true, "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Indicators", "query": "", "queryType": "input", "readOnly": true, "static": false, "type": "indicators", "w": 2, "x": 0, "y": 3 }, { "displayType": "ROW", "h": 3, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-0e149ea0-9d8e-11e9-a715-f7bbe72c84a2", "isVisible": true, "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Email HTML Image", "query": { "tags": [ "email_html_image" ] }, "queryType": "warRoomFilter", "readOnly": true, "static": false, "type": "invTimeline", "w": 1, "x": 1, "y": 0 }, { "h": 3, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-b5924880-df88-11e9-9d3d-b355b2831118", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "URL Screenshots", "query": { "tags": [ "url_screenshots" ] }, "queryType": "warRoomFilter", "static": false, "type": "invTimeline", "w": 1, "x": 2, "y": 0 }, { "description": "", "h": 1, "hideName": true, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-044bccb0-befa-11eb-b351-7bcfe92e5e24", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Related Phishing Campaign", "query": "LinkToPhishingCampaign", "queryType": "script", "static": false, "type": "dynamic", "w": 1, "x": 2, "y": 5 }, { "h": 2, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-e78cf650-a8fd-11ec-927e-2bbbcff3899b", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Work Plan", "static": false, "type": "workplan", "w": 1, "x": 2, "y": 6 }, { "displayType": "ROW", "h": 2, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-93d51e60-a8fe-11ec-927e-2bbbcff3899b", "items": [ { "endCol": 2, "fieldId": "reportedemailto", "height": 22, "id": "fdb6d7e0-adbf-11ec-9b0d-458b8734eabf", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "reportedemailmessageid", "height": 22, "id": "b2b6dc90-adbf-11ec-9b0d-458b8734eabf", "index": 1, "listId": "swtuqptgvs-1vduzkpmlh-93d51e60-a8fe-11ec-927e-2bbbcff3899b", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "emaildeletetype", "height": 22, "id": "d30b3a90-adbf-11ec-9b0d-458b8734eabf", "index": 2, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "emaildeletefrombrand", "height": 22, "id": "51e6d7d0-af45-11ec-99c4-cfc9ad59fcf6", "index": 3, "sectionItemType": "field", "startCol": 0 }, { "args": { "delete_from_brand": { "complex": { "accessor": "sourcebrand", "filters": [], "root": "incident", "transformers": [] } }, "delete_type": { "complex": { "accessor": "emaildeletetype", "filters": [], "root": "incident", "transformers": [] } } }, "buttonClass": "error", "dropEffect": "move", "endCol": 2, "fieldId": "", "height": 44, "id": "df048e20-a8fe-11ec-927e-2bbbcff3899b", "index": 4, "listId": "swtuqptgvs-1vduzkpmlh-93d51e60-a8fe-11ec-927e-2bbbcff3899b", "name": "Delete email", "scriptId": "DeleteReportedEmail", "sectionItemType": "button", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Response action", "static": false, "w": 1, "x": 2, "y": 8 }, { "displayType": "ROW", "h": 2, "hideName": false, "i": "swtuqptgvs-field-changed-swtuqptgvs-68df82f0-a902-11ec-8585-0dac7af6e9b0", "items": [ { "endCol": 2, "fieldId": "emaildeleteresult", "height": 22, "id": "0ef499c0-adc0-11ec-9b0d-458b8734eabf", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "emaildeletereason", "height": 22, "id": "10429d90-adc0-11ec-9b0d-458b8734eabf", "index": 1, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Email Delete Result", "static": false, "w": 1, "x": 2, "y": 10 }, { "columns": [ { "displayed": true, "isDefault": true, "key": "id", "width": 109 }, { "displayed": true, "isDefault": true, "key": "name", "width": 336 }, { "displayed": true, "isDefault": true, "key": "type", "width": 200 }, { "displayed": true, "isDefault": true, "key": "status", "width": 100 }, { "displayed": true, "key": "Reported Email To", "width": 200 }, { "displayed": true, "key": "Reported Email From", "width": 200 }, { "displayed": true, "key": "Reported Email Message ID", "width": 368 }, { "displayed": true, "isDefault": true, "key": "closeNotes", "width": 300 } ], "h": 2, "i": "swtuqptgvs-field-changed-swtuqptgvs-8f724f40-6b37-11ed-b7c0-2904efd8f7fb", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Linked Incidents", "static": false, "type": "linkedIncidents", "w": 3, "x": 0, "y": 16 }, { "description": "Indicators selected to be blocked.", "h": 2, "i": "swtuqptgvs-1a52c090-c187-11ed-a413-1fc9f082fba8", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Selected indicators to block", "query": "tags:\"Blocked Indicator In Systems\"", "queryType": "input", "static": false, "type": "indicators", "w": 1, "x": 2, "y": 14 }, { "description": ":warning: This section contains the original HTML of the email. Links may lead to malicious websites!", "h": 6, "i": "swtuqptgvs-ca48f510-f322-11ed-8c15-d92844a806b0", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "Email Body", "query": "DisplayHTMLWithImages", "queryType": "script", "static": false, "type": "dynamic", "w": 2, "x": 0, "y": 8 }, { "displayType": "CARD", "h": 2, "hideName": false, "i": "swtuqptgvs-20ca76d0-02e5-11ee-8d4d-65992a7b968b", "items": [ { "dropEffect": "move", "endCol": 2, "fieldId": "triagesla", "height": 53, "id": "39e688c0-02e5-11ee-8d4d-65992a7b968b", "index": 1, "listId": "swtuqptgvs-20ca76d0-02e5-11ee-8d4d-65992a7b968b", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "remediationsla", "height": 53, "id": "37bf6300-02e5-11ee-8d4d-65992a7b968b", "index": 2, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "detectionsla", "height": 53, "id": "361116c0-02e5-11ee-8d4d-65992a7b968b", "index": 0, "listId": "swtuqptgvs-20ca76d0-02e5-11ee-8d4d-65992a7b968b", "sectionItemType": "field", "startCol": 1 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Incident SLAs", "static": false, "w": 1, "x": 2, "y": 12 } ], "type": "custom" }, { "hidden": false, "id": "fn7ljmkjwi", "name": "Investigation", "sections": [ { "description": "Headers extracted from the original email.", "displayType": "ROW", "h": 5, "hideItemTitleOnlyOne": true, "hideName": false, "i": "swtuqptgvs-12668f30-a903-11ec-8585-0dac7af6e9b0", "items": [ { "endCol": 4, "fieldId": "emailheaders", "height": 106, "id": "1b9a3610-a903-11ec-8585-0dac7af6e9b0", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Email Headers", "static": false, "w": 2, "x": 0, "y": 0 }, { "description": "Analysis of SPF, DKIM, DMARC and Microsoft anti-spam headers.\n\nFor Microsoft anti-spam headers, please click on each item for the relevant documentation:\n[PCL](https://docs.microsoft.com/en-us/exchange/antispam-and-antimalware/antispam-protection/antispam-stamps?view=exchserver-2019) - Phishing Confidence Level.\n[BCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/bulk-complaint-level-values?view=o365-worldwide) - Bulk Complaint Level.\n[SCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels?view=o365-worldwide) - Spam Confidence Level.\n`Note`: The default value is 0, but it can be changed when the \"Process Microsoft's Email Headers\" playbook runs.", "displayType": "CARD", "h": 3, "hideName": false, "i": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0", "items": [ { "dropEffect": "move", "endCol": 1, "fieldId": "emailauthenticitycheck", "height": 53, "id": "e81fede0-a905-11ec-8585-0dac7af6e9b0", "index": 0, "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 1, "fieldId": "phishingbclscore", "height": 53, "id": "753052e0-a903-11ec-8585-0dac7af6e9b0", "index": 1, "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "phishingsclscore", "height": 53, "id": "738f2600-a903-11ec-8585-0dac7af6e9b0", "index": 0, "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 1 }, { "dropEffect": "move", "endCol": 2, "fieldId": "phishingpclscore", "height": 53, "id": "779062f0-a903-11ec-8585-0dac7af6e9b0", "index": 2, "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 1 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Headers Analysis", "static": false, "w": 1, "x": 2, "y": 0 }, { "description": "Results of machine-learning checks on the email using a pretrained model.", "displayType": "CARD", "h": 3, "hideName": false, "i": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0", "items": [ { "dropEffect": "move", "endCol": 1, "fieldId": "dbotpredictionprobability", "height": 53, "id": "e9282b90-a904-11ec-8585-0dac7af6e9b0", "index": 0, "listId": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 1, "fieldId": "dbotprediction", "height": 53, "id": "e4e7c2c0-a904-11ec-8585-0dac7af6e9b0", "index": 1, "listId": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "dbottextsuggestionhighlighted", "height": 106, "id": "fa1f2070-a904-11ec-8585-0dac7af6e9b0", "index": 2, "listId": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "ML Prediction For The Email", "static": false, "w": 1, "x": 0, "y": 8 }, { "description": "The category of the email. In case of a phishing email, also shows the phishing sub-type.", "displayType": "ROW", "h": 3, "hideName": false, "i": "swtuqptgvs-4b078f40-a905-11ec-8585-0dac7af6e9b0", "items": [ { "endCol": 2, "fieldId": "emailclassification", "height": 22, "id": "6f45aa90-a905-11ec-8585-0dac7af6e9b0", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 4, "fieldId": "phishingsubtype", "height": 22, "id": "79e23040-a905-11ec-8585-0dac7af6e9b0", "index": 2, "sectionItemType": "field", "startCol": 2 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Email Type Information", "static": false, "w": 1, "x": 2, "y": 6 }, { "displayType": "ROW", "h": 5, "hideItemTitleOnlyOne": true, "hideName": false, "i": "swtuqptgvs-86ec81a0-a905-11ec-8585-0dac7af6e9b0", "items": [ { "endCol": 4, "fieldId": "emailhtml", "height": 44, "id": "b3eb0fa0-a905-11ec-8585-0dac7af6e9b0", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Raw Email HTML", "static": false, "w": 2, "x": 0, "y": 11 }, { "displayType": "ROW", "h": 2, "hideItemTitleOnlyOne": true, "hideName": false, "i": "swtuqptgvs-8b9776a0-a906-11ec-8585-0dac7af6e9b0", "items": [ { "dropEffect": "move", "endCol": 2, "fieldId": "emailkeywordsfound", "height": 22, "id": "2a056410-fedc-11ed-80a2-5b21992c1654", "index": 0, "listId": "swtuqptgvs-8b9776a0-a906-11ec-8585-0dac7af6e9b0", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "domainsquattingresult", "height": 44, "id": "9aca7460-a906-11ec-8585-0dac7af6e9b0", "index": 1, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Spear Phishing Investigation", "static": false, "w": 1, "x": 2, "y": 3 }, { "description": "Provides machine-learning based detection of phishing URLs (shows only malicious detections).", "h": 3, "i": "swtuqptgvs-d2300fd0-b5a1-11ec-9a46-87b4f35ed7e4", "items": [], "maxW": 3, "minH": 1, "moved": false, "name": "ML Prediction for URLs", "query": { "notTags": [], "tags": [ "DBOT_URL_PHISHING_MALICIOUS" ] }, "queryType": "warRoomFilter", "static": false, "type": "invTimeline", "w": 1, "x": 1, "y": 8 }, { "description": "In case a macro code was found in any of the attachments, the source code will appear here.", "displayType": "CARD", "h": 8, "hideName": false, "i": "swtuqptgvs-2b388350-4a26-11ed-9b10-cf167480534f", "items": [ { "endCol": 2, "fieldId": "macrosourcecode", "height": 22, "id": "59b96b90-4a26-11ed-9b10-cf167480534f", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Macro Source Code", "static": false, "w": 1, "x": 2, "y": 9 }, { "description": "In case there were URLs in the email with a score of 3 or above which the user clicked for the email investigated in this incident, they will appear in the **Clicked URLs** table. **Total Malicious URLs Clicks** represents the number of clicks in all emails (other emails as well) associated with any of the malicious URLs found in this email. **Malicious URL Viewed** will be **True** if the click was allowed or the user clicked through, in case it was blocked.", "displayType": "CARD", "h": 3, "hideName": false, "i": "swtuqptgvs-791f4a20-5d1a-11ed-936b-2d907795e2cc", "items": [ { "endCol": 1, "fieldId": "maliciousurlclicked", "height": 53, "id": "c0b24f80-8b4c-11ed-8d12-ef934cb7154e", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 4, "fieldId": "clickedurls", "height": 106, "id": "e4f91d60-8b4c-11ed-8d12-ef934cb7154e", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "maliciousurlviewed", "height": 53, "id": "e9800930-8c09-11ed-bd41-2b7339c8983d", "index": 0, "sectionItemType": "field", "startCol": 1 }, { "endCol": 3, "fieldId": "totalmaliciousurlsclicks", "height": 53, "id": "409da7d0-8b4d-11ed-8d12-ef934cb7154e", "index": 1, "sectionItemType": "field", "startCol": 2 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Malicious Clicked URLs information", "static": false, "w": 2, "x": 0, "y": 5 }, { "description": "", "displayType": "ROW", "h": 1, "hideName": false, "i": "swtuqptgvs-fn7ljmkjwi-swtuqptgvs-fn7ljmkjwi-swtuqptgvs-ed6ea880-fec8-11ed-8c2c-79dd47ae5c19", "items": [ { "endCol": 2, "fieldId": "relatedcampaign", "height": 22, "id": "02a542e0-fec9-11ed-8c2c-79dd47ae5c19", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "relatedreport", "height": 22, "id": "07dc19a0-fec9-11ed-8c2c-79dd47ae5c19", "index": 1, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Threat Intelligence Analysis", "static": false, "w": 1, "x": 2, "y": 5 } ], "type": "custom" }, { "id": "warRoom", "name": "War Room", "type": "warRoom" }, { "id": "workPlan", "name": "Work Plan", "type": "workPlan" }, { "id": "evidenceBoard", "name": "Evidence Board", "type": "evidenceBoard" }, { "id": "relatedIncidents", "name": "Related Incidents", "type": "relatedIncidents" }, { "id": "canvas", "name": "Canvas", "type": "canvas" } ] }, "edit": { "sections": [ { "description": "Trigger the incident based on a phishing email attachment.\n\nPlease fill in:\n1. A name of the incident.\n2. The email address for which you're making the report (optional).\n3. An EML or MSG file representing the phishing email, or containing another EML or MSG file of the phishing email within it.\n\nIf the reporter email address is left blank - user engagement will be skipped in the playbook.", "fields": [ { "fieldId": "incident_name", "isVisible": true }, { "fieldId": "incident_reporteremailaddress", "isVisible": true }, { "fieldId": "incident_attachment", "isVisible": true } ], "isVisible": true, "name": "Add a phishing email", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "Optional - details regarding the incident itself (not specific to phishing).", "fields": [ { "fieldId": "incident_occurred", "isVisible": true }, { "fieldId": "incident_owner", "isVisible": true }, { "fieldId": "incident_type", "isVisible": true }, { "fieldId": "incident_severity", "isVisible": true }, { "fieldId": "incident_playbookid", "isVisible": true }, { "fieldId": "incident_details", "isVisible": true } ], "isVisible": true, "name": "Incident Metadata", "query": null, "queryType": "", "readOnly": false, "type": "" } ] }, "group": "incident", "id": "Phishing Incident v3", "mobile": { "sections": [ { "description": "General information about the incident.", "fields": [ { "fieldId": "incident_type", "isVisible": true }, { "fieldId": "incident_severity", "isVisible": true }, { "fieldId": "incident_owner", "isVisible": true }, { "fieldId": "incident_dbotstatus", "isVisible": true }, { "fieldId": "incident_sourcebrand", "isVisible": true }, { "fieldId": "incident_sourceinstance", "isVisible": true }, { "fieldId": "incident_playbookid", "isVisible": true }, { "fieldId": "incident_phase", "isVisible": true }, { "fieldId": "incident_roles", "isVisible": true } ], "isVisible": true, "name": "Incident Information", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "Information about the phishing email that was received.", "fields": [ { "fieldId": "incident_emailfrom", "isVisible": true }, { "fieldId": "incident_emailto", "isVisible": true }, { "fieldId": "incident_emailcc", "isVisible": true }, { "fieldId": "incident_reporteremailaddress", "isVisible": true }, { "fieldId": "incident_emailsubject", "isVisible": true }, { "fieldId": "incident_emailbody", "isVisible": true }, { "fieldId": "incident_emailhtml", "isVisible": true }, { "fieldId": "incident_emailauthenticitycheck", "isVisible": true }, { "fieldId": "incident_emailinreplyto", "isVisible": true }, { "fieldId": "incident_emailreturnpath", "isVisible": true } ], "isVisible": true, "name": "Email", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "Information about file attachments in the phishing email.", "fields": [ { "fieldId": "incident_attachmentname", "isVisible": true }, { "fieldId": "incident_attachmenttype", "isVisible": true }, { "fieldId": "incident_attachmentsize", "isVisible": true } ], "isVisible": true, "name": "Attachments", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "Time information about the incident.", "fields": [ { "fieldId": "incident_occurred", "isVisible": true }, { "fieldId": "incident_dbotcreated", "isVisible": true }, { "fieldId": "incident_dbotduedate", "isVisible": true }, { "fieldId": "incident_dbotmodified", "isVisible": true }, { "fieldId": "incident_dbottotaltime", "isVisible": true }, { "fieldId": "incident_detectionsla", "isVisible": true }, { "fieldId": "incident_remediationsla", "isVisible": true }, { "fieldId": "incident_timetoassignment", "isVisible": true } ], "isVisible": true, "name": "Timeline \u0026 SLA", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "", "fields": [ { "fieldId": "incident_labels", "isVisible": true } ], "isVisible": true, "name": "Labels", "query": null, "queryType": "", "readOnly": true, "type": "labels" } ] }, "name": "Phishing Incident v3", "quickView": { "sections": [ { "description": "Information about the phishing email that was received.", "fields": [ { "fieldId": "incident_emailfrom", "isVisible": true }, { "fieldId": "incident_emailto", "isVisible": true }, { "fieldId": "incident_reporteremailaddress", "isVisible": true }, { "fieldId": "incident_emailsubject", "isVisible": true }, { "fieldId": "incident_emailbody", "isVisible": true }, { "fieldId": "incident_attachmentname", "isVisible": true }, { "fieldId": "incident_attachmenttype", "isVisible": true }, { "fieldId": "incident_attachmentsize", "isVisible": true } ], "isVisible": true, "name": "Email Information", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "", "fields": [ { "fieldId": "incident_dbotcreated", "isVisible": true }, { "fieldId": "incident_occurred", "isVisible": true }, { "fieldId": "incident_dbotduedate", "isVisible": true }, { "fieldId": "incident_dbotmodified", "isVisible": true }, { "fieldId": "incident_dbottotaltime", "isVisible": true } ], "isVisible": true, "name": "Timeline Information", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "Information about Service Level Agreements (SLAs).", "fields": [ { "fieldId": "incident_detectionsla", "isVisible": true }, { "fieldId": "incident_remediationsla", "isVisible": true }, { "fieldId": "incident_timetoassignment", "isVisible": true } ], "isVisible": true, "name": "SLA", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "", "fields": [ { "fieldId": "incident_labels", "isVisible": true } ], "isVisible": true, "name": "Labels", "query": null, "queryType": "", "readOnly": true, "type": "labels" } ] }, "system": false, "version": -1, "fromVersion": "6.1.0", "marketplaces": [ "xsoar" ], "description": "" }