Phishing Layout

The default layout for phishing incidents.

Phishing Incident

Details

IDPhishing Layout
Groupincident
Version-1
From Version6.10.0

Layout Structure

Legacy Summary 0 sections

No sections defined.

Alert Details 7 sections

Alert Details

Field IDPosition
type Col 0-2, Height: 26
reportedemailorigin Col 0-2, Height: 26
severity Col 0-2, Height: 26
sourcebrand Col 0-2, Height: 26
sourceinstance Col 0-2, Height: 26
owner Col 0-2, Height: 26

Notes

Work Plan

Indicators

Timeline Information

Field IDPosition
occurred Col 0-1, Height: 53
dbotduedate Col 0-1, Height: 53
dbotmodified Col 1-2, Height: 53
dbotcreated Col 1-2, Height: 53

Closing Information

Field IDPosition
dbotclosed Col 0-2, Height: 26
closereason Col 0-2, Height: 26
closenotes Col 0-2, Height: 26

Blocked Indicators

Indicators that the user selected to block, when blocking is done in manual (default) mode.

Email Details 8 sections

Email Information

Field IDPosition
reportedemailfrom Col 0-2, Height: 26
reportedemailto Col 0-2, Height: 26
emailsubject Col 0-2, Height: 26
reporteremailaddress Col 0-2, Height: 26
emailcc Col 0-2, Height: 26
emailbcc Col 0-2, Height: 26
emailrecipientscount Col 0-2, Height: 26

Attachment Information

Information about attachments extracted from the reported email.

Field IDPosition
attachmentname Col 0-2, Height: 26
attachmentextension Col 0-2, Height: 26
attachmenttype Col 0-2, Height: 26
attachmentsize Col 0-2, Height: 26
attachmenthash Col 0-2, Height: 26

Attachments

All file attachments of the email, and the email file itself if it was attached or retrieved.

Field IDPosition
incident_attachment Col 0-2, Height: 53

Alert Scope

Email & URL Screenshots

Email HTML

:warning: This section contains the original HTML of the email. Links may lead to malicious websites!

Action Center

If executed, the email corresponding to the Message ID below will be deleted from the mailbox of the user specified below.

Field IDPosition
reportedemailto Col 0-2, Height: 26
emailsubject Col 0-2, Height: 26
reportedemailmessageid Col 0-2, Height: 26
emaildeletetype Col 0-2, Height: 26
emaildeletefrombrand Col 0-2, Height: 26
Col 0-2, Height: 44

Email Delete Result

Field IDPosition
emaildeleteresult Col 0-2, Height: 26
emaildeletereason Col 0-2, Height: 26
Email Analysis 7 sections

Raw Email HTML

Field IDPosition
emailhtml Col 0-4, Height: 52

Email Headers

Field IDPosition
emailheaders Col 0-4, Height: 106

Header Analysis

Analysis of SPF, DKIM, DMARC and Microsoft anti-spam headers. For Microsoft anti-spam headers, please click on each item for the relevant documentation: [PCL](https://docs.microsoft.com/en-us/exchange/antispam-and-antimalware/antispam-protection/antispam-stamps?view=exchserver-2019) - Phishing Confidence Level. [BCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/bulk-complaint-level-values?view=o365-worldwide) - Bulk Complaint Level. [SCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels?view=o365-worldwide) - Spam Confidence Level. `Note`: The default value is 0, but it can be changed when the "Process Microsoft's Email Headers" playbook runs.

Field IDPosition
emailauthenticitycheck Col 0-1, Height: 53
phishingbclscore Col 0-1, Height: 53
phishingpclscore Col 1-2, Height: 53
phishingsclscore Col 1-2, Height: 53

Threat Intelligence Analysis

Field IDPosition
relatedcampaign Col 0-2, Height: 26
relatedreport Col 0-2, Height: 26

Macro Source Code

Field IDPosition
macrosourcecode Col 0-2, Height: 26

Malicious URL Clicks

Requires the **Microsoft 365 Defender** integration.

Field IDPosition
maliciousurlviewed Col 0-1, Height: 53
clickedurls Col 0-4, Height: 106
maliciousurlclicked Col 1-2, Height: 53
totalmaliciousurlsclicks Col 2-3, Height: 53

Investigation Insights

Field IDPosition
emailkeywords Col 0-2, Height: 26
domainsquattingresult Col 0-2, Height: 26
War Room 0 sections

No sections defined.

Work Plan 0 sections

No sections defined.

Canvas 0 sections

No sections defined.

{
    "description": "The default layout for phishing incidents.",
    "detailsV2": {
        "tabs": [
            {
                "id": "summary",
                "name": "Legacy Summary",
                "type": "summary"
            },
            {
                "id": "qoey6clq4l",
                "name": "Alert Details",
                "sections": [
                    {
                        "description": "",
                        "displayType": "ROW",
                        "h": 2,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-fce71720-98b0-11e9-97d7-ed26ef9e46c8",
                        "isVisible": true,
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "type",
                                "height": 26,
                                "id": "incident-type-field",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "reportedemailorigin",
                                "height": 26,
                                "id": "69c68fc0-78ad-11ee-83ba-e99e7220b301",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "severity",
                                "height": 26,
                                "id": "incident-severity-field",
                                "index": 2,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "sourcebrand",
                                "height": 26,
                                "id": "incident-sourceBrand-field",
                                "index": 3,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "sourceinstance",
                                "height": 26,
                                "id": "incident-sourceInstance-field",
                                "index": 4,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "owner",
                                "height": 26,
                                "id": "incident-owner-field",
                                "index": 5,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "moved": false,
                        "name": "Alert Details",
                        "static": false,
                        "w": 1,
                        "x": 0,
                        "y": 0
                    },
                    {
                        "h": 2,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-61263cc0-98b1-11e9-97d7-ed26ef9e46c8",
                        "maxW": 3,
                        "moved": false,
                        "name": "Notes",
                        "static": false,
                        "type": "notes",
                        "w": 1,
                        "x": 2,
                        "y": 4
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-6aabad20-98b1-11e9-97d7-ed26ef9e46c8",
                        "maxW": 3,
                        "moved": false,
                        "name": "Work Plan",
                        "static": false,
                        "type": "workplan",
                        "w": 1,
                        "x": 2,
                        "y": 0
                    },
                    {
                        "displayType": "ROW",
                        "h": 6,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-7ce69dd0-a07f-11e9-936c-5395a1acf11e",
                        "maxW": 3,
                        "moved": false,
                        "name": "Indicators",
                        "query": "",
                        "queryType": "input",
                        "static": false,
                        "type": "indicators",
                        "w": 2,
                        "x": 0,
                        "y": 2
                    },
                    {
                        "displayType": "CARD",
                        "h": 2,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-ac32f620-a0b0-11e9-b27f-13ae1773d289",
                        "items": [
                            {
                                "endCol": 1,
                                "fieldId": "occurred",
                                "height": 53,
                                "id": "0339c950-730a-11ee-a22e-872f04e65504",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 1,
                                "fieldId": "dbotduedate",
                                "height": 53,
                                "id": "incident-dueDate-field",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "dbotmodified",
                                "height": 53,
                                "id": "incident-modified-field",
                                "index": 0,
                                "listId": "caseinfoid-ac32f620-a0b0-11e9-b27f-13ae1773d289",
                                "sectionItemType": "field",
                                "startCol": 1
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "dbotcreated",
                                "height": 53,
                                "id": "incident-created-field",
                                "index": 1,
                                "listId": "caseinfoid-ac32f620-a0b0-11e9-b27f-13ae1773d289",
                                "sectionItemType": "field",
                                "startCol": 1
                            }
                        ],
                        "maxW": 3,
                        "moved": false,
                        "name": "Timeline Information",
                        "static": false,
                        "w": 1,
                        "x": 1,
                        "y": 0
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-88e6bf70-a0b1-11e9-b27f-13ae1773d289",
                        "isVisible": true,
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "dbotclosed",
                                "height": 26,
                                "id": "incident-dbotClosed-field",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "closereason",
                                "height": 26,
                                "id": "incident-closeReason-field",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "closenotes",
                                "height": 26,
                                "id": "incident-closeNotes-field",
                                "index": 2,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "moved": false,
                        "name": "Closing Information",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 6
                    },
                    {
                        "description": "Indicators that the user selected to block, when blocking is done in manual (default) mode.",
                        "h": 2,
                        "i": "qoey6clq4l-17422030-7668-11ee-953f-9166c9f595d1",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Blocked Indicators",
                        "query": "tags:\"Blocked Indicator In Systems\"",
                        "queryType": "input",
                        "static": false,
                        "type": "indicators",
                        "w": 1,
                        "x": 2,
                        "y": 2
                    }
                ],
                "type": "custom"
            },
            {
                "id": "caseinfoid",
                "name": "Email Details",
                "sections": [
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": false,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-f11047e0-7309-11ee-a22e-872f04e65504",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "reportedemailfrom",
                                "height": 26,
                                "id": "5cd84dc0-730e-11ee-a22e-872f04e65504",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "reportedemailto",
                                "height": 26,
                                "id": "1b19e690-730f-11ee-a22e-872f04e65504",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "emailsubject",
                                "height": 26,
                                "id": "29301bf0-730a-11ee-a22e-872f04e65504",
                                "index": 2,
                                "listId": "qoey6clq4l-olzmwfmu0d-caseinfoid-f11047e0-7309-11ee-a22e-872f04e65504",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "reporteremailaddress",
                                "height": 26,
                                "id": "384be830-730a-11ee-a22e-872f04e65504",
                                "index": 3,
                                "listId": "qoey6clq4l-olzmwfmu0d-caseinfoid-f11047e0-7309-11ee-a22e-872f04e65504",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emailcc",
                                "height": 26,
                                "id": "81c30ba0-7662-11ee-953f-9166c9f595d1",
                                "index": 4,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emailbcc",
                                "height": 26,
                                "id": "801a64b0-7662-11ee-953f-9166c9f595d1",
                                "index": 5,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "emailrecipientscount",
                                "height": 26,
                                "id": "ae6b6350-7662-11ee-953f-9166c9f595d1",
                                "index": 6,
                                "listId": "qoey6clq4l-olzmwfmu0d-caseinfoid-f11047e0-7309-11ee-a22e-872f04e65504",
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email Information",
                        "static": false,
                        "w": 1,
                        "wrapLabels": true,
                        "x": 0,
                        "y": 0
                    },
                    {
                        "description": "Information about attachments extracted from the reported email.",
                        "displayType": "ROW",
                        "h": 3,
                        "hideName": false,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-ac5bc040-730c-11ee-a22e-872f04e65504",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "attachmentname",
                                "height": 26,
                                "id": "d4dcdc70-730c-11ee-a22e-872f04e65504",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "attachmentextension",
                                "height": 26,
                                "id": "d361ae20-730c-11ee-a22e-872f04e65504",
                                "index": 1,
                                "listId": "caseinfoid-ac5bc040-730c-11ee-a22e-872f04e65504",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "attachmenttype",
                                "height": 26,
                                "id": "449c1150-730a-11ee-a22e-872f04e65504",
                                "index": 2,
                                "listId": "caseinfoid-f11047e0-7309-11ee-a22e-872f04e65504",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "attachmentsize",
                                "height": 26,
                                "id": "d7901590-730c-11ee-a22e-872f04e65504",
                                "index": 3,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "attachmenthash",
                                "height": 26,
                                "id": "dd827420-730c-11ee-a22e-872f04e65504",
                                "index": 4,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Attachment Information",
                        "static": false,
                        "w": 1,
                        "wrapLabels": false,
                        "x": 0,
                        "y": 5
                    },
                    {
                        "description": "All file attachments of the email, and the email file itself if it was attached or retrieved.",
                        "displayType": "CARD",
                        "h": 2,
                        "hideItemTitleOnlyOne": true,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-c8881f70-730c-11ee-a22e-872f04e65504",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "incident_attachment",
                                "height": 53,
                                "id": "c8811a91-730c-11ee-a22e-872f04e65504",
                                "index": 0,
                                "isVisible": true,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Attachments",
                        "static": false,
                        "type": "",
                        "w": 1,
                        "x": 0,
                        "y": 3
                    },
                    {
                        "description": "",
                        "h": 1,
                        "hideName": true,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-7bec8010-730d-11ee-a22e-872f04e65504",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Alert Scope",
                        "query": "LinkToPhishingCampaign",
                        "queryType": "script",
                        "static": false,
                        "type": "dynamic",
                        "w": 1,
                        "x": 0,
                        "y": 2
                    },
                    {
                        "h": 5,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-58e10f00-7326-11ee-ae15-4554156b85ba",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email & URL Screenshots",
                        "query": {
                            "categories": [
                                "tags"
                            ],
                            "preDefinedFilters": true,
                            "tags": [
                                "url_screenshots",
                                "email_html_image"
                            ]
                        },
                        "queryType": "warRoomFilter",
                        "static": false,
                        "type": "invTimeline",
                        "w": 1,
                        "x": 1,
                        "y": 3
                    },
                    {
                        "description": ":warning: This section contains the original HTML of the email. Links may lead to malicious websites!",
                        "h": 3,
                        "i": "qoey6clq4l-olzmwfmu0d-caseinfoid-1193c500-7332-11ee-ae15-4554156b85ba",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email HTML",
                        "query": "DisplayHTMLWithImages",
                        "queryType": "script",
                        "static": false,
                        "type": "dynamic",
                        "w": 2,
                        "x": 1,
                        "y": 0
                    },
                    {
                        "description": "If executed, the email corresponding to the Message ID below will be deleted from the mailbox of the user specified below.",
                        "displayType": "ROW",
                        "h": 3,
                        "hideItemTitleOnlyOne": false,
                        "hideName": false,
                        "i": "qoey6clq4l-10903f00-7664-11ee-953f-9166c9f595d1",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "reportedemailto",
                                "height": 26,
                                "id": "44caa090-77da-11ee-8948-f393fb37ff06",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emailsubject",
                                "height": 26,
                                "id": "21edcd80-77db-11ee-8948-f393fb37ff06",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "reportedemailmessageid",
                                "height": 26,
                                "id": "7d926f60-7664-11ee-953f-9166c9f595d1",
                                "index": 2,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emaildeletetype",
                                "height": 26,
                                "id": "868fc400-7664-11ee-953f-9166c9f595d1",
                                "index": 2,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emaildeletefrombrand",
                                "height": 26,
                                "id": "8c010bb0-7664-11ee-953f-9166c9f595d1",
                                "index": 3,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "args": {
                                    "delete_from_brand": {
                                        "simple": "${alert.sourcebrand}"
                                    },
                                    "delete_type": {
                                        "simple": "${alert.emaildeletetype}"
                                    },
                                    "polling": {
                                        "simple": "true"
                                    },
                                    "search_name": {
                                        "simple": "Search & Delete Executed from XSIAM alert layout."
                                    }
                                },
                                "buttonClass": null,
                                "endCol": 2,
                                "fieldId": "",
                                "height": 44,
                                "hexColor": "#b20000",
                                "id": "923b96d0-7664-11ee-953f-9166c9f595d1",
                                "index": 4,
                                "name": "Delete Email",
                                "scriptId": "DeleteReportedEmail",
                                "sectionItemType": "button",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Action Center",
                        "static": false,
                        "w": 1,
                        "wrapLabels": true,
                        "x": 2,
                        "y": 3
                    },
                    {
                        "description": "",
                        "displayType": "CARD",
                        "h": 2,
                        "hideName": false,
                        "i": "qoey6clq4l-4d2c2fe0-7665-11ee-953f-9166c9f595d1",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "emaildeleteresult",
                                "height": 26,
                                "id": "66aafb40-7665-11ee-953f-9166c9f595d1",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emaildeletereason",
                                "height": 26,
                                "id": "67c719a0-7665-11ee-953f-9166c9f595d1",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email Delete Result",
                        "static": false,
                        "w": 1,
                        "wrapLabels": true,
                        "x": 2,
                        "y": 6
                    }
                ],
                "type": "custom"
            },
            {
                "hidden": false,
                "id": "opvds8dnjq",
                "name": "Email Analysis",
                "sections": [
                    {
                        "displayType": "ROW",
                        "h": 5,
                        "hideName": false,
                        "i": "qoey6clq4l-caseinfoid-20aaaf10-730d-11ee-a22e-872f04e65504",
                        "items": [
                            {
                                "endCol": 4,
                                "fieldId": "emailhtml",
                                "height": 52,
                                "id": "33b36cf0-730d-11ee-a22e-872f04e65504",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Raw Email HTML",
                        "static": false,
                        "w": 2,
                        "x": 0,
                        "y": 7
                    },
                    {
                        "description": "",
                        "displayType": "ROW",
                        "h": 4,
                        "hideItemTitleOnlyOne": true,
                        "hideName": false,
                        "i": "qoey6clq4l-caseinfoid-42d26d80-730d-11ee-a22e-872f04e65504",
                        "items": [
                            {
                                "endCol": 4,
                                "fieldId": "emailheaders",
                                "height": 106,
                                "id": "4c56f380-730d-11ee-a22e-872f04e65504",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email Headers",
                        "static": false,
                        "w": 2,
                        "x": 0,
                        "y": 0
                    },
                    {
                        "description": "Analysis of SPF, DKIM, DMARC and Microsoft anti-spam headers.\n\nFor Microsoft anti-spam headers, please click on each item for the relevant documentation:\n\n[PCL](https://docs.microsoft.com/en-us/exchange/antispam-and-antimalware/antispam-protection/antispam-stamps?view=exchserver-2019) - Phishing Confidence Level.\n\n[BCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/bulk-complaint-level-values?view=o365-worldwide) - Bulk Complaint Level.\n\n[SCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels?view=o365-worldwide) - Spam Confidence Level.\n\n`Note`: The default value is 0, but it can be changed when the \"Process Microsoft's Email Headers\" playbook runs.",
                        "displayType": "CARD",
                        "h": 4,
                        "hideName": false,
                        "i": "qoey6clq4l-caseinfoid-66229470-730f-11ee-a22e-872f04e65504",
                        "items": [
                            {
                                "endCol": 1,
                                "fieldId": "emailauthenticitycheck",
                                "height": 53,
                                "id": "c8cb62a0-730f-11ee-a22e-872f04e65504",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 1,
                                "fieldId": "phishingbclscore",
                                "height": 53,
                                "id": "d13fff40-730f-11ee-a22e-872f04e65504",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "phishingpclscore",
                                "height": 53,
                                "id": "d44fb040-730f-11ee-a22e-872f04e65504",
                                "index": 0,
                                "listId": "caseinfoid-66229470-730f-11ee-a22e-872f04e65504",
                                "sectionItemType": "field",
                                "startCol": 1
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "phishingsclscore",
                                "height": 53,
                                "id": "cd6cfe40-730f-11ee-a22e-872f04e65504",
                                "index": 1,
                                "listId": "caseinfoid-66229470-730f-11ee-a22e-872f04e65504",
                                "sectionItemType": "field",
                                "startCol": 1
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Header Analysis",
                        "static": false,
                        "w": 1,
                        "wrapLabels": false,
                        "x": 2,
                        "y": 0
                    },
                    {
                        "description": "",
                        "displayType": "ROW",
                        "h": 1,
                        "hideName": false,
                        "i": "qoey6clq4l-fbd09aa0-7669-11ee-953f-9166c9f595d1",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "relatedcampaign",
                                "height": 26,
                                "id": "481184f0-766b-11ee-953f-9166c9f595d1",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "relatedreport",
                                "height": 26,
                                "id": "4a5d49b0-766b-11ee-953f-9166c9f595d1",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Threat Intelligence Analysis",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 4
                    },
                    {
                        "description": "",
                        "displayType": "ROW",
                        "h": 5,
                        "hideItemTitleOnlyOne": true,
                        "hideName": false,
                        "i": "qoey6clq4l-25c29a00-766c-11ee-953f-9166c9f595d1",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "macrosourcecode",
                                "height": 26,
                                "id": "b5ad6bc0-7704-11ee-8d8f-35fb0a410368",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Macro Source Code",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 7
                    },
                    {
                        "description": "Requires the **Microsoft 365 Defender** integration.",
                        "displayType": "CARD",
                        "h": 3,
                        "hideName": false,
                        "i": "qoey6clq4l-907471c0-766c-11ee-953f-9166c9f595d1",
                        "items": [
                            {
                                "dropEffect": "move",
                                "endCol": 1,
                                "fieldId": "maliciousurlviewed",
                                "height": 53,
                                "id": "ad987760-766c-11ee-953f-9166c9f595d1",
                                "index": 0,
                                "listId": "qoey6clq4l-907471c0-766c-11ee-953f-9166c9f595d1",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 4,
                                "fieldId": "clickedurls",
                                "height": 106,
                                "id": "d3b516b0-766c-11ee-953f-9166c9f595d1",
                                "index": 2,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "maliciousurlclicked",
                                "height": 53,
                                "id": "abcedaf0-766c-11ee-953f-9166c9f595d1",
                                "index": 0,
                                "listId": "qoey6clq4l-907471c0-766c-11ee-953f-9166c9f595d1",
                                "sectionItemType": "field",
                                "startCol": 1
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 3,
                                "fieldId": "totalmaliciousurlsclicks",
                                "height": 53,
                                "id": "b79f4cc0-766c-11ee-953f-9166c9f595d1",
                                "index": 0,
                                "listId": "qoey6clq4l-907471c0-766c-11ee-953f-9166c9f595d1",
                                "sectionItemType": "field",
                                "startCol": 2
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Malicious URL Clicks",
                        "static": false,
                        "w": 2,
                        "wrapLabels": false,
                        "x": 0,
                        "y": 4
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": false,
                        "i": "qoey6clq4l-3e81de90-766f-11ee-953f-9166c9f595d1",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "emailkeywords",
                                "height": 26,
                                "id": "af4cd6c0-766f-11ee-953f-9166c9f595d1",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "domainsquattingresult",
                                "height": 26,
                                "id": "b21ee280-766f-11ee-953f-9166c9f595d1",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Investigation Insights",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 5
                    }
                ],
                "showEmptyFields": true,
                "type": "custom"
            },
            {
                "id": "warRoom",
                "name": "War Room",
                "type": "warRoom"
            },
            {
                "id": "workPlan",
                "name": "Work Plan",
                "type": "workPlan"
            },
            {
                "id": "canvas",
                "name": "Canvas",
                "type": "canvas",
                "hidden": false
            }
        ]
    },
    "group": "incident",
    "id": "Phishing Layout",
    "name": "Phishing Layout",
    "system": false,
    "version": -1,
    "marketplaces": [
        "marketplacev2",
        "platform"
    ],
    "fromVersion": "6.10.0"
}