Phishing - Indicators Hunting

Hunt indicators related to phishing with available integrations and then handle the results. Handling the results will include setting relevant incident fields which will be displayed in the layout and optionally, opening new incidents according to the findings. Current integration in this playbook: - Microsoft 365 Defender (using "Advanced Hunting") Note that this playbook should be used as a sub-playbook inside a phishing incident and not as a main playbook.

Pack
Phishing
Tasks
5

Inputs