Phishing Incident

Phishing Incident

Details

IDPhishing
Groupincident
Version-1
From Version6.0.0

Layout Structure

Case info 9 sections

Case Details

Field IDPosition
type Col 0-2, Height: 24
severity Col 0-2, Height: 24
owner Col 0-2, Height: 24
dbotsource Col 0-2, Height: 24
sourceinstance Col 0-2, Height: 24
sourcebrand Col 0-2, Height: 24
playbookid Col 0-2, Height: 24

Notes

Work Plan

Linked Incidents

Child Incidents

Evidence

Team Members

Timeline Information

Field IDPosition
occurred Col 0-2, Height: 24
dbotcreated Col 0-2, Height: 24
dbotmodified Col 0-2, Height: 24
dbotclosed Col 0-2, Height: 24
remediationsla Col 0-2, Height: 24
dbotduedate Col 0-2, Height: 24
detectionsla Col 0-2, Height: 24

Closing Information

Field IDPosition
dbotclosed Col 0-2, Height: 24
closereason Col 0-2, Height: 24
closinguserid Col 0-2, Height: 24
closenotes Col 0-2, Height: 48
Investigation 16 sections

Raw Email HTML

Field IDPosition
emailhtml Col 0-2, Height: 110

Email Text

Field IDPosition
emailbody Col 0-2, Height: 110

Email Basic Information

Field IDPosition
emailfrom Col 0-2, Height: 22
emailto Col 0-2, Height: 22
emailsubject Col 0-2, Height: 22
emailcc Col 0-2, Height: 22
emailbcc Col 0-2, Height: 22
emailreplyto Col 0-2, Height: 22
emailreturnpath Col 0-2, Height: 22
emailmessageid Col 0-2, Height: 22
reporteremailaddress Col 0-2, Height: 22
emailsenderip Col 0-2, Height: 22
emailtocount Col 0-2, Height: 22

Email Attachments

Field IDPosition
attachment Col 0-2, Height: 55
attachmenthash Col 0-2, Height: 24
attachmentname Col 0-2, Height: 24
attachmentsize Col 0-2, Height: 24
attachmentextension Col 0-2, Height: 24
attachmenttype Col 0-2, Height: 24

Incident Files

Indicators

Number of incidents per email address

Email HTML Image

Email Type Information

The category of the email. In case of a phishing email, also shows the phishing sub-type.

Field IDPosition
phishingsubtype Col 0-2, Height: 24
emailclassification Col 0-2, Height: 24

URL Screenshots

Email Authenticity Information

The result of SPF, DKIM and DMARC checks on the email.

Field IDPosition
emailauthenticitycheck Col 0-2, Height: 55

Critical Assets

Critical Assets that were found, at the investigation stage, to be involved in the incident.

Field IDPosition
criticalassets Col 0-2, Height: 110

Machine-learning Predictions

Field IDPosition
dbotprediction Col 0-2, Height: 24
dbotpredictionprobability Col 0-2, Height: 24
dbottextsuggestionhighlighted Col 0-2, Height: 24

Email Headers

Headers extracted from the original email.

Field IDPosition
emailheaders Col 0-6, Height: 106

Related Phishing Campaign

Microsoft Anti-Spam Headers

PCL - Phishing Confidence Level (4-8: The message content is likely to be phishing.) BCL - Bulk complaint level (4-7: The message is from a bulk sender that generates a mixed number of complaints. 8-9: The message is from a bulk sender that generates a high number of complaints.) SCL - Spam confidence level (5-6: Spam filtering marked the message as Spam. 9: Spam filtering marked the message as High confidence spam)

Field IDPosition
phishingsclscore Col 0-2, Height: 22
phishingbclscore Col 0-2, Height: 22
phishingpclscore Col 0-2, Height: 22
War Room 0 sections

No sections defined.

Work Plan 0 sections

No sections defined.

Evidence Board 0 sections

No sections defined.

Related Incidents 0 sections

No sections defined.

Canvas 0 sections

No sections defined.

Classic Summary 0 sections

No sections defined.

{
    "detailsV2": {
        "tabs": [
            {
                "hidden": false,
                "id": "summary",
                "name": "Classic Summary",
                "type": "summary"
            },
            {
                "hidden": false,
                "id": "swtuqptgvs",
                "name": "Case info",
                "sections": [
                    {
                        "displayType": "CARD",
                        "h": 2,
                        "hideItemTitleOnlyOne": true,
                        "hideName": false,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-57f33cc0-97ee-11e9-b8bd-0b00be54d2d3",
                        "isVisible": true,
                        "items": [
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "attachment",
                                "height": 53,
                                "id": "9cd0f990-ac6b-11e9-bb03-dd1b065c10a8",
                                "index": 0,
                                "listId": "swtuqptgvs-49052550-97f0-11e9-b8bd-0b00be54d2d3",
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email Attachments",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 3
                    },
                    {
                        "displayType": "ROW",
                        "h": 3,
                        "hideName": false,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3",
                        "isVisible": true,
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "occurred",
                                "height": 22,
                                "id": "418772e0-a901-11ec-8585-0dac7af6e9b0",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "severity",
                                "height": 22,
                                "id": "45ef12c0-a901-11ec-8585-0dac7af6e9b0",
                                "index": 1,
                                "listId": "swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "owner",
                                "height": 22,
                                "id": "4b1ac5f0-a901-11ec-8585-0dac7af6e9b0",
                                "index": 2,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "reportedemailorigin",
                                "height": 22,
                                "id": "b8f3e800-6279-11ec-8fa2-217b8b611613",
                                "index": 3,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "reportedemailfrom",
                                "height": 22,
                                "id": "be942ef0-6279-11ec-8fa2-217b8b611613",
                                "index": 4,
                                "listId": "swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "reportedemailto",
                                "height": 22,
                                "id": "c2ce0810-6279-11ec-8fa2-217b8b611613",
                                "index": 5,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "reportedemailcc",
                                "height": 22,
                                "id": "b6f8e8b0-a901-11ec-8585-0dac7af6e9b0",
                                "index": 6,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "reporteremailaddress",
                                "height": 22,
                                "id": "93c5bbb0-df83-11e9-9d3d-b355b2831118",
                                "index": 7,
                                "listId": "swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-d431b9b0-97ee-11e9-b8bd-0b00be54d2d3",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emailbcc",
                                "height": 22,
                                "id": "2bd969b0-879c-11ed-b4ee-6db51deb2f6e",
                                "index": 8,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "reportedemailsubject",
                                "height": 22,
                                "id": "02f6f6c0-111c-11ee-a4d9-8dbe5c55933f",
                                "index": 9,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "attachmentcount",
                                "height": 22,
                                "id": "86ae8b10-a901-11ec-8585-0dac7af6e9b0",
                                "index": 10,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emailrecipientscount",
                                "height": 22,
                                "id": "77a63970-6279-11ec-8fa2-217b8b611613",
                                "index": 11,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "additionalemailaddresses",
                                "height": 26,
                                "id": "c477b540-d63e-11ee-a660-f13ca793ceb6",
                                "index": 11,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "categories",
                                "height": 22,
                                "id": "5e2287d0-e502-11ed-ba0f-99a713ead7dc",
                                "index": 12,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Case Basic Details",
                        "static": false,
                        "w": 1,
                        "x": 0,
                        "y": 0
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": false,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-067d4900-98b4-11e9-97d7-ed26ef9e46c8",
                        "isVisible": true,
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Incident Files",
                        "query": {
                            "categories": [
                                "attachments"
                            ],
                            "notTags": [
                                "email_html_image",
                                "url_screenshots"
                            ],
                            "tags": [],
                            "tagsAndOperator": true
                        },
                        "queryType": "warRoomFilter",
                        "readOnly": true,
                        "static": false,
                        "type": "invTimeline",
                        "w": 2,
                        "x": 0,
                        "y": 14
                    },
                    {
                        "displayType": "ROW",
                        "h": 5,
                        "hideName": false,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-cc557320-98b7-11e9-b34a-852d068f44fe",
                        "isVisible": true,
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Indicators",
                        "query": "",
                        "queryType": "input",
                        "readOnly": true,
                        "static": false,
                        "type": "indicators",
                        "w": 2,
                        "x": 0,
                        "y": 3
                    },
                    {
                        "displayType": "ROW",
                        "h": 3,
                        "hideName": false,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-0e149ea0-9d8e-11e9-a715-f7bbe72c84a2",
                        "isVisible": true,
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email HTML Image",
                        "query": {
                            "tags": [
                                "email_html_image"
                            ]
                        },
                        "queryType": "warRoomFilter",
                        "readOnly": true,
                        "static": false,
                        "type": "invTimeline",
                        "w": 1,
                        "x": 1,
                        "y": 0
                    },
                    {
                        "h": 3,
                        "hideName": false,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-b5924880-df88-11e9-9d3d-b355b2831118",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "URL Screenshots",
                        "query": {
                            "tags": [
                                "url_screenshots"
                            ]
                        },
                        "queryType": "warRoomFilter",
                        "static": false,
                        "type": "invTimeline",
                        "w": 1,
                        "x": 2,
                        "y": 0
                    },
                    {
                        "description": "",
                        "h": 1,
                        "hideName": true,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-swtuqptgvs-1vduzkpmlh-swtuqptgvs-044bccb0-befa-11eb-b351-7bcfe92e5e24",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Related Phishing Campaign",
                        "query": "LinkToPhishingCampaign",
                        "queryType": "script",
                        "static": false,
                        "type": "dynamic",
                        "w": 1,
                        "x": 2,
                        "y": 5
                    },
                    {
                        "h": 2,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-e78cf650-a8fd-11ec-927e-2bbbcff3899b",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Work Plan",
                        "static": false,
                        "type": "workplan",
                        "w": 1,
                        "x": 2,
                        "y": 6
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": false,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-1vduzkpmlh-93d51e60-a8fe-11ec-927e-2bbbcff3899b",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "reportedemailto",
                                "height": 22,
                                "id": "fdb6d7e0-adbf-11ec-9b0d-458b8734eabf",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "reportedemailmessageid",
                                "height": 22,
                                "id": "b2b6dc90-adbf-11ec-9b0d-458b8734eabf",
                                "index": 1,
                                "listId": "swtuqptgvs-1vduzkpmlh-93d51e60-a8fe-11ec-927e-2bbbcff3899b",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emaildeletetype",
                                "height": 22,
                                "id": "d30b3a90-adbf-11ec-9b0d-458b8734eabf",
                                "index": 2,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emaildeletefrombrand",
                                "height": 22,
                                "id": "51e6d7d0-af45-11ec-99c4-cfc9ad59fcf6",
                                "index": 3,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "args": {
                                    "delete_from_brand": {
                                        "complex": {
                                            "accessor": "sourcebrand",
                                            "filters": [],
                                            "root": "incident",
                                            "transformers": []
                                        }
                                    },
                                    "delete_type": {
                                        "complex": {
                                            "accessor": "emaildeletetype",
                                            "filters": [],
                                            "root": "incident",
                                            "transformers": []
                                        }
                                    }
                                },
                                "buttonClass": "error",
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "",
                                "height": 44,
                                "id": "df048e20-a8fe-11ec-927e-2bbbcff3899b",
                                "index": 4,
                                "listId": "swtuqptgvs-1vduzkpmlh-93d51e60-a8fe-11ec-927e-2bbbcff3899b",
                                "name": "Delete email",
                                "scriptId": "DeleteReportedEmail",
                                "sectionItemType": "button",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Response action",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 8
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideName": false,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-68df82f0-a902-11ec-8585-0dac7af6e9b0",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "emaildeleteresult",
                                "height": 22,
                                "id": "0ef499c0-adc0-11ec-9b0d-458b8734eabf",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "emaildeletereason",
                                "height": 22,
                                "id": "10429d90-adc0-11ec-9b0d-458b8734eabf",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email Delete Result",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 10
                    },
                    {
                        "columns": [
                            {
                                "displayed": true,
                                "isDefault": true,
                                "key": "id",
                                "width": 109
                            },
                            {
                                "displayed": true,
                                "isDefault": true,
                                "key": "name",
                                "width": 336
                            },
                            {
                                "displayed": true,
                                "isDefault": true,
                                "key": "type",
                                "width": 200
                            },
                            {
                                "displayed": true,
                                "isDefault": true,
                                "key": "status",
                                "width": 100
                            },
                            {
                                "displayed": true,
                                "key": "Reported Email To",
                                "width": 200
                            },
                            {
                                "displayed": true,
                                "key": "Reported Email From",
                                "width": 200
                            },
                            {
                                "displayed": true,
                                "key": "Reported Email Message ID",
                                "width": 368
                            },
                            {
                                "displayed": true,
                                "isDefault": true,
                                "key": "closeNotes",
                                "width": 300
                            }
                        ],
                        "h": 2,
                        "i": "swtuqptgvs-field-changed-swtuqptgvs-8f724f40-6b37-11ed-b7c0-2904efd8f7fb",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Linked Incidents",
                        "static": false,
                        "type": "linkedIncidents",
                        "w": 3,
                        "x": 0,
                        "y": 16
                    },
                    {
                        "description": "Indicators selected to be blocked.",
                        "h": 2,
                        "i": "swtuqptgvs-1a52c090-c187-11ed-a413-1fc9f082fba8",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Selected indicators to block",
                        "query": "tags:\"Blocked Indicator In Systems\"",
                        "queryType": "input",
                        "static": false,
                        "type": "indicators",
                        "w": 1,
                        "x": 2,
                        "y": 14
                    },
                    {
                        "description": ":warning: This section contains the original HTML of the email. Links may lead to malicious websites!",
                        "h": 6,
                        "i": "swtuqptgvs-ca48f510-f322-11ed-8c15-d92844a806b0",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email Body",
                        "query": "DisplayHTMLWithImages",
                        "queryType": "script",
                        "static": false,
                        "type": "dynamic",
                        "w": 2,
                        "x": 0,
                        "y": 8
                    },
                    {
                        "displayType": "CARD",
                        "h": 2,
                        "hideName": false,
                        "i": "swtuqptgvs-20ca76d0-02e5-11ee-8d4d-65992a7b968b",
                        "items": [
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "triagesla",
                                "height": 53,
                                "id": "39e688c0-02e5-11ee-8d4d-65992a7b968b",
                                "index": 1,
                                "listId": "swtuqptgvs-20ca76d0-02e5-11ee-8d4d-65992a7b968b",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "remediationsla",
                                "height": 53,
                                "id": "37bf6300-02e5-11ee-8d4d-65992a7b968b",
                                "index": 2,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "detectionsla",
                                "height": 53,
                                "id": "361116c0-02e5-11ee-8d4d-65992a7b968b",
                                "index": 0,
                                "listId": "swtuqptgvs-20ca76d0-02e5-11ee-8d4d-65992a7b968b",
                                "sectionItemType": "field",
                                "startCol": 1
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Incident SLAs",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 12
                    }
                ],
                "type": "custom"
            },
            {
                "hidden": false,
                "id": "fn7ljmkjwi",
                "name": "Investigation",
                "sections": [
                    {
                        "description": "Headers extracted from the original email.",
                        "displayType": "ROW",
                        "h": 5,
                        "hideItemTitleOnlyOne": true,
                        "hideName": false,
                        "i": "swtuqptgvs-12668f30-a903-11ec-8585-0dac7af6e9b0",
                        "items": [
                            {
                                "endCol": 4,
                                "fieldId": "emailheaders",
                                "height": 106,
                                "id": "1b9a3610-a903-11ec-8585-0dac7af6e9b0",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email Headers",
                        "static": false,
                        "w": 2,
                        "x": 0,
                        "y": 0
                    },
                    {
                        "description": "Analysis of SPF, DKIM, DMARC and Microsoft anti-spam headers.\n\nFor Microsoft anti-spam headers, please click on each item for the relevant documentation:\n[PCL](https://docs.microsoft.com/en-us/exchange/antispam-and-antimalware/antispam-protection/antispam-stamps?view=exchserver-2019) - Phishing Confidence Level.\n[BCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/bulk-complaint-level-values?view=o365-worldwide) - Bulk Complaint Level.\n[SCL](https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels?view=o365-worldwide) - Spam Confidence Level.\n`Note`: The default value is 0, but it can be changed when the \"Process Microsoft's Email Headers\" playbook runs.",
                        "displayType": "CARD",
                        "h": 3,
                        "hideName": false,
                        "i": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0",
                        "items": [
                            {
                                "dropEffect": "move",
                                "endCol": 1,
                                "fieldId": "emailauthenticitycheck",
                                "height": 53,
                                "id": "e81fede0-a905-11ec-8585-0dac7af6e9b0",
                                "index": 0,
                                "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 1,
                                "fieldId": "phishingbclscore",
                                "height": 53,
                                "id": "753052e0-a903-11ec-8585-0dac7af6e9b0",
                                "index": 1,
                                "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "phishingsclscore",
                                "height": 53,
                                "id": "738f2600-a903-11ec-8585-0dac7af6e9b0",
                                "index": 0,
                                "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0",
                                "sectionItemType": "field",
                                "startCol": 1
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "phishingpclscore",
                                "height": 53,
                                "id": "779062f0-a903-11ec-8585-0dac7af6e9b0",
                                "index": 2,
                                "listId": "swtuqptgvs-2f561750-a903-11ec-8585-0dac7af6e9b0",
                                "sectionItemType": "field",
                                "startCol": 1
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Headers Analysis",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 0
                    },
                    {
                        "description": "Results of machine-learning checks on the email using a pretrained model.",
                        "displayType": "CARD",
                        "h": 3,
                        "hideName": false,
                        "i": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0",
                        "items": [
                            {
                                "dropEffect": "move",
                                "endCol": 1,
                                "fieldId": "dbotpredictionprobability",
                                "height": 53,
                                "id": "e9282b90-a904-11ec-8585-0dac7af6e9b0",
                                "index": 0,
                                "listId": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 1,
                                "fieldId": "dbotprediction",
                                "height": 53,
                                "id": "e4e7c2c0-a904-11ec-8585-0dac7af6e9b0",
                                "index": 1,
                                "listId": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "dbottextsuggestionhighlighted",
                                "height": 106,
                                "id": "fa1f2070-a904-11ec-8585-0dac7af6e9b0",
                                "index": 2,
                                "listId": "swtuqptgvs-84947d50-a904-11ec-8585-0dac7af6e9b0",
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "ML Prediction For The Email",
                        "static": false,
                        "w": 1,
                        "x": 0,
                        "y": 8
                    },
                    {
                        "description": "The category of the email. In case of a phishing email, also shows the phishing sub-type.",
                        "displayType": "ROW",
                        "h": 3,
                        "hideName": false,
                        "i": "swtuqptgvs-4b078f40-a905-11ec-8585-0dac7af6e9b0",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "emailclassification",
                                "height": 22,
                                "id": "6f45aa90-a905-11ec-8585-0dac7af6e9b0",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 4,
                                "fieldId": "phishingsubtype",
                                "height": 22,
                                "id": "79e23040-a905-11ec-8585-0dac7af6e9b0",
                                "index": 2,
                                "sectionItemType": "field",
                                "startCol": 2
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Email Type Information",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 6
                    },
                    {
                        "displayType": "ROW",
                        "h": 5,
                        "hideItemTitleOnlyOne": true,
                        "hideName": false,
                        "i": "swtuqptgvs-86ec81a0-a905-11ec-8585-0dac7af6e9b0",
                        "items": [
                            {
                                "endCol": 4,
                                "fieldId": "emailhtml",
                                "height": 44,
                                "id": "b3eb0fa0-a905-11ec-8585-0dac7af6e9b0",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Raw Email HTML",
                        "static": false,
                        "w": 2,
                        "x": 0,
                        "y": 11
                    },
                    {
                        "displayType": "ROW",
                        "h": 2,
                        "hideItemTitleOnlyOne": true,
                        "hideName": false,
                        "i": "swtuqptgvs-8b9776a0-a906-11ec-8585-0dac7af6e9b0",
                        "items": [
                            {
                                "dropEffect": "move",
                                "endCol": 2,
                                "fieldId": "emailkeywordsfound",
                                "height": 22,
                                "id": "2a056410-fedc-11ed-80a2-5b21992c1654",
                                "index": 0,
                                "listId": "swtuqptgvs-8b9776a0-a906-11ec-8585-0dac7af6e9b0",
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "domainsquattingresult",
                                "height": 44,
                                "id": "9aca7460-a906-11ec-8585-0dac7af6e9b0",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Spear Phishing Investigation",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 3
                    },
                    {
                        "description": "Provides machine-learning based detection of phishing URLs (shows only malicious detections).",
                        "h": 3,
                        "i": "swtuqptgvs-d2300fd0-b5a1-11ec-9a46-87b4f35ed7e4",
                        "items": [],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "ML Prediction for URLs",
                        "query": {
                            "notTags": [],
                            "tags": [
                                "DBOT_URL_PHISHING_MALICIOUS"
                            ]
                        },
                        "queryType": "warRoomFilter",
                        "static": false,
                        "type": "invTimeline",
                        "w": 1,
                        "x": 1,
                        "y": 8
                    },
                    {
                        "description": "In case a macro code was found in any of the attachments, the source code will appear here.",
                        "displayType": "CARD",
                        "h": 8,
                        "hideName": false,
                        "i": "swtuqptgvs-2b388350-4a26-11ed-9b10-cf167480534f",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "macrosourcecode",
                                "height": 22,
                                "id": "59b96b90-4a26-11ed-9b10-cf167480534f",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Macro Source Code",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 9
                    },
                    {
                        "description": "In case there were URLs in the email with a score of 3 or above which the user clicked for the email investigated in this incident, they will appear in the **Clicked URLs** table. **Total Malicious URLs Clicks** represents the number of clicks in all emails (other emails as well) associated with any of the malicious URLs found in this email. **Malicious URL Viewed** will be **True** if the click was allowed or the user clicked through, in case it was blocked.",
                        "displayType": "CARD",
                        "h": 3,
                        "hideName": false,
                        "i": "swtuqptgvs-791f4a20-5d1a-11ed-936b-2d907795e2cc",
                        "items": [
                            {
                                "endCol": 1,
                                "fieldId": "maliciousurlclicked",
                                "height": 53,
                                "id": "c0b24f80-8b4c-11ed-8d12-ef934cb7154e",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 4,
                                "fieldId": "clickedurls",
                                "height": 106,
                                "id": "e4f91d60-8b4c-11ed-8d12-ef934cb7154e",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "maliciousurlviewed",
                                "height": 53,
                                "id": "e9800930-8c09-11ed-bd41-2b7339c8983d",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 1
                            },
                            {
                                "endCol": 3,
                                "fieldId": "totalmaliciousurlsclicks",
                                "height": 53,
                                "id": "409da7d0-8b4d-11ed-8d12-ef934cb7154e",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 2
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Malicious Clicked URLs information",
                        "static": false,
                        "w": 2,
                        "x": 0,
                        "y": 5
                    },
                    {
                        "description": "",
                        "displayType": "ROW",
                        "h": 1,
                        "hideName": false,
                        "i": "swtuqptgvs-fn7ljmkjwi-swtuqptgvs-fn7ljmkjwi-swtuqptgvs-ed6ea880-fec8-11ed-8c2c-79dd47ae5c19",
                        "items": [
                            {
                                "endCol": 2,
                                "fieldId": "relatedcampaign",
                                "height": 22,
                                "id": "02a542e0-fec9-11ed-8c2c-79dd47ae5c19",
                                "index": 0,
                                "sectionItemType": "field",
                                "startCol": 0
                            },
                            {
                                "endCol": 2,
                                "fieldId": "relatedreport",
                                "height": 22,
                                "id": "07dc19a0-fec9-11ed-8c2c-79dd47ae5c19",
                                "index": 1,
                                "sectionItemType": "field",
                                "startCol": 0
                            }
                        ],
                        "maxW": 3,
                        "minH": 1,
                        "moved": false,
                        "name": "Threat Intelligence Analysis",
                        "static": false,
                        "w": 1,
                        "x": 2,
                        "y": 5
                    }
                ],
                "type": "custom"
            },
            {
                "id": "warRoom",
                "name": "War Room",
                "type": "warRoom"
            },
            {
                "id": "workPlan",
                "name": "Work Plan",
                "type": "workPlan"
            },
            {
                "id": "evidenceBoard",
                "name": "Evidence Board",
                "type": "evidenceBoard"
            },
            {
                "id": "relatedIncidents",
                "name": "Related Incidents",
                "type": "relatedIncidents"
            },
            {
                "id": "canvas",
                "name": "Canvas",
                "type": "canvas"
            }
        ]
    },
    "edit": {
        "sections": [
            {
                "description": "Trigger the incident based on a phishing email attachment.\n\nPlease fill in:\n1. A name of the incident.\n2. The email address for which you're making the report (optional).\n3. An EML or MSG file representing the phishing email, or containing another EML or MSG file of the phishing email within it.\n\nIf the reporter email address is left blank - user engagement will be skipped in the playbook.",
                "fields": [
                    {
                        "fieldId": "incident_name",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_reporteremailaddress",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_attachment",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "Add a phishing email",
                "query": null,
                "queryType": "",
                "readOnly": false,
                "type": ""
            },
            {
                "description": "Optional - details regarding the incident itself (not specific to phishing).",
                "fields": [
                    {
                        "fieldId": "incident_occurred",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_owner",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_type",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_severity",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_playbookid",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_details",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "Incident Metadata",
                "query": null,
                "queryType": "",
                "readOnly": false,
                "type": ""
            }
        ]
    },
    "group": "incident",
    "id": "Phishing Incident v3",
    "mobile": {
        "sections": [
            {
                "description": "General information about the incident.",
                "fields": [
                    {
                        "fieldId": "incident_type",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_severity",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_owner",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_dbotstatus",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_sourcebrand",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_sourceinstance",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_playbookid",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_phase",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_roles",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "Incident Information",
                "query": null,
                "queryType": "",
                "readOnly": false,
                "type": ""
            },
            {
                "description": "Information about the phishing email that was received.",
                "fields": [
                    {
                        "fieldId": "incident_emailfrom",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailto",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailcc",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_reporteremailaddress",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailsubject",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailbody",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailhtml",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailauthenticitycheck",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailinreplyto",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailreturnpath",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "Email",
                "query": null,
                "queryType": "",
                "readOnly": false,
                "type": ""
            },
            {
                "description": "Information about file attachments in the phishing email.",
                "fields": [
                    {
                        "fieldId": "incident_attachmentname",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_attachmenttype",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_attachmentsize",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "Attachments",
                "query": null,
                "queryType": "",
                "readOnly": false,
                "type": ""
            },
            {
                "description": "Time information about the incident.",
                "fields": [
                    {
                        "fieldId": "incident_occurred",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_dbotcreated",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_dbotduedate",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_dbotmodified",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_dbottotaltime",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_detectionsla",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_remediationsla",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_timetoassignment",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "Timeline \u0026 SLA",
                "query": null,
                "queryType": "",
                "readOnly": false,
                "type": ""
            },
            {
                "description": "",
                "fields": [
                    {
                        "fieldId": "incident_labels",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "Labels",
                "query": null,
                "queryType": "",
                "readOnly": true,
                "type": "labels"
            }
        ]
    },
    "name": "Phishing Incident v3",
    "quickView": {
        "sections": [
            {
                "description": "Information about the phishing email that was received.",
                "fields": [
                    {
                        "fieldId": "incident_emailfrom",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailto",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_reporteremailaddress",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailsubject",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_emailbody",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_attachmentname",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_attachmenttype",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_attachmentsize",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "Email Information",
                "query": null,
                "queryType": "",
                "readOnly": false,
                "type": ""
            },
            {
                "description": "",
                "fields": [
                    {
                        "fieldId": "incident_dbotcreated",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_occurred",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_dbotduedate",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_dbotmodified",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_dbottotaltime",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "Timeline Information",
                "query": null,
                "queryType": "",
                "readOnly": false,
                "type": ""
            },
            {
                "description": "Information about Service Level Agreements (SLAs).",
                "fields": [
                    {
                        "fieldId": "incident_detectionsla",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_remediationsla",
                        "isVisible": true
                    },
                    {
                        "fieldId": "incident_timetoassignment",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "SLA",
                "query": null,
                "queryType": "",
                "readOnly": false,
                "type": ""
            },
            {
                "description": "",
                "fields": [
                    {
                        "fieldId": "incident_labels",
                        "isVisible": true
                    }
                ],
                "isVisible": true,
                "name": "Labels",
                "query": null,
                "queryType": "",
                "readOnly": true,
                "type": "labels"
            }
        ]
    },
    "system": false,
    "version": -1,
    "fromVersion": "6.1.0",
    "marketplaces": [
        "xsoar"
    ],
    "description": ""
}