MITRE ATT&CK CoA - T1566 - Phishing

This playbook Remediates the Phishing technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. ***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Techniques Handled: - T1566: Phishing Kill Chain phases: - Initial Access MITRE ATT&CK Description: Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns. Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems or to gather credentials for use of Valid Accounts. Phishing may also be conducted via third-party services, like social media platforms. Possible playbook uses: - The playbook can be used independently to handle and remediate the specific technique. - The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

MITRE ATT&CK - Courses of Action · 20 tasks · 4 inputs · 1 output

Details

IDMITRE ATT&CK CoA - T1566 - Phishing
From Version6.5.0
Tasks20

README

This playbook Remediates the Phishing technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.

***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:

  • T1566: Phishing

Kill Chain phases:

  • Initial Access

MITRE ATT&CK Description:

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Adversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems or to gather credentials for use of Valid Accounts. Phishing may also be conducted via third-party services, like social media platforms.

Possible playbook uses:

  • The playbook can be used independently to handle and remediate the specific technique.
  • The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
  • The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Phishing Investigation - Generic v2
  • PAN-OS - Enforce Anti-Virus Best Practices Profile
  • PAN-OS - Enforce WildFire Best Practices Profile
  • Endpoint Malware Investigation - Generic

Integrations

This playbook does not use any integrations.

Scripts

  • Set
  • IsIntegrationAvailable
  • SetGridField

Commands

This playbook does not use any commands.

Playbook Inputs


Name Description Default Value Required
template Template name to enforce WildFire best practices profile.   Optional
pre_post Rules location. Can be ‘pre-rulebase’ or ‘post-rulebase’. Mandatory for Panorama instances.   Optional
device-group The device group for which to return addresses (Panorama instances).   Optional
tag Tag for which to filter the results.   Optional

Playbook Outputs


Path Description Type
Handled.Techniques The techniques handled in this playbook unknown

Playbook Image


MITRE ATT&CK CoA - T1566 - Phishing

Inputs

  • template — Template name to enforce WildFire best practices profile.
  • pre_post — Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.
  • device-group — The device group for which to return addresses (Panorama instances).
  • tag — Tag for which to filter the results.

Outputs

  • Handled.Techniques — The techniques handled in this playbook

Flowchart

yes yes yes Start Start Manual - Cortex XDR - Setup file blocking Manual - Cortex XDR - Set... PAN-OS - Enforce Anti-Virus Best Practices Profile - PAN-OS - Enforce Anti-Virus Best Practices Profile PAN-OS - Enforce Anti-Vir... PAN-OS - Enforce Anti-Virus B... PAN-OS - Enforce WildFire Best Practices Profile - PAN-OS - Enforce WildFire Best Practices Profile PAN-OS - Enforce WildFire... PAN-OS - Enforce WildFire Bes... Manual - Cortex XDR - Configure Malware Security Profile Manual - Cortex XDR - Con... Phishing Investigation - Generic v2 - Phishing Investigation - Generic v2 Phishing Investigation - ... Phishing Investigation - Gene... Endpoint Malware Investigation - Generic - Endpoint Malware Investigation - Generic Endpoint Malware Investig... Endpoint Malware Investigatio... Would you like to use "Phishing Investigation - Generic v2? Would you like to use "Ph... Would you like to use "Access Investigation - Generic" playbook? Would you like to use "Ac... Set technique handled Set technique handled Deploy Cortex XSOAR Playbook – Phishing Investigation - Generic v2 Deploy Cortex XSOAR Playb... Deploy Cortex XSOAR Playbook – Endpoint Malware Investigation - Generic Deploy Cortex XSOAR Playb... Setup file blocking in Cortex XDR Setup file blocking in Co... PAN-OS - Enforce Anti-Virus Best Practices Profile PAN-OS - Enforce Anti-Vir... PAN-OS - Enforce WildFire Best Practices Profile PAN-OS - Enforce WildFire... Configure Malware Security Profile in Cortex XDR Configure Malware Securit... Done Done Is Cortex XDR integration Enabled? Is Cortex XDR integration... Manual - Enable Cortex XDR integration Manual - Enable Cortex XD... Set grid field Set grid field
description: "This playbook Remediates the Phishing technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.\n \n***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\nTechniques Handled:\n- T1566: Phishing\n\nKill Chain phases:\n- Initial Access\n\nMITRE ATT&CK Description:\n\nAdversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.\n\nAdversaries may send victims emails containing malicious attachments or links, typically to execute malicious code on victim systems or to gather credentials for use of Valid Accounts. Phishing may also be conducted via third-party services, like social media platforms.\n\nPossible playbook uses:\n- The playbook can be used independently to handle and remediate the specific technique.\n- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input."
id: MITRE ATT&CK CoA - T1566 - Phishing
inputs:
- description: Template name to enforce WildFire best practices profile.
  key: template
  playbookInputQuery:
  required: false
  value: {}
- description: Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.
  key: pre_post
  playbookInputQuery:
  required: false
  value: {}
- description: The device group for which to return addresses (Panorama instances).
  key: device-group
  playbookInputQuery:
  required: false
  value: {}
- description: Tag for which to filter the results.
  key: tag
  playbookInputQuery:
  required: false
  value: {}
name: MITRE ATT&CK CoA - T1566 - Phishing
outputs:
- contextPath: Handled.Techniques
  description: The techniques handled in this playbook
  type: unknown
starttaskid: "0"
tasks:
  "0":
    id: "0"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "17"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      id: 19c8b9f6-1020-4d9f-8dc3-15f634ddc14d
      iscommand: false
      name: ""
      version: -1
      description: ''
    taskid: 19c8b9f6-1020-4d9f-8dc3-15f634ddc14d
    timertriggers: []
    type: start
    view: |-
      {
        "position": {
          "x": 450,
          "y": -830
        }
      }
  "1":
    id: "1"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "13"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      description: Manual - Cortex XDR - Setup file blocking.
      id: 2d53375f-b379-440c-8281-faf27f7446de
      iscommand: false
      name: Manual - Cortex XDR - Setup file blocking
      type: regular
      version: -1
    taskid: 2d53375f-b379-440c-8281-faf27f7446de
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 450,
          "y": -190
        }
      }
  "2":
    id: "2"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "14"
    note: false
    quietmode: 0
    scriptarguments:
      ApplyToRule:
        complex:
          root: inputs.ApplyToRule
      device-group:
        complex:
          root: inputs.device-group
      pre-post-rulebase:
        complex:
          root: inputs.pre_post
      rule_name:
        complex:
          root: inputs.rule_name
      tag:
        complex:
          root: inputs.tag
    separatecontext: true
    skipunavailable: true
    task:
      brand: ""
      id: 19a97534-0d96-4cf1-8f13-fdbc812f1cb5
      iscommand: false
      name: PAN-OS - Enforce Anti-Virus Best Practices Profile
      playbookId: PAN-OS - Enforce Anti-Virus Best Practices Profile
      type: playbook
      version: -1
      description: ''
    taskid: 19a97534-0d96-4cf1-8f13-fdbc812f1cb5
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 450,
          "y": 120
        }
      }
  "3":
    id: "3"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "15"
    note: false
    quietmode: 0
    scriptarguments:
      ApplyToRule:
        complex:
          root: inputs.ApplyToRule
      device-group:
        complex:
          root: inputs.device-group
      pre-post-rulebase:
        complex:
          root: inputs.pre_post
      rule_name:
        complex:
          root: inputs.rule_name
      tag:
        complex:
          root: inputs.tag
      template:
        complex:
          root: inputs.template
    separatecontext: true
    skipunavailable: true
    task:
      brand: ""
      id: 0b5f3a2e-2d36-4f2e-8c0c-2e036e05f07d
      iscommand: false
      name: PAN-OS - Enforce WildFire Best Practices Profile
      playbookId: PAN-OS - Enforce WildFire Best Practices Profile
      type: playbook
      version: -1
      description: ''
    taskid: 0b5f3a2e-2d36-4f2e-8c0c-2e036e05f07d
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 450,
          "y": 440
        }
      }
  "4":
    id: "4"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "7"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      description: Manual - Cortex XDR - Configure Malware Security Profile.
      id: e9bb301a-76b9-4f38-8741-eb8ed4e1cd27
      iscommand: false
      name: Manual - Cortex XDR - Configure Malware Security Profile
      type: regular
      version: -1
    taskid: e9bb301a-76b9-4f38-8741-eb8ed4e1cd27
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 450,
          "y": 750
        }
      }
  "5":
    id: "5"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "8"
    note: false
    quietmode: 0
    scriptarguments:
      AuthenticateEmail:
        simple: "False"
      BlockIndicators:
        simple: "False"
      OnCall:
        simple: "false"
      Role:
        simple: Administrator
      SearchAndDelete:
        simple: "False"
    separatecontext: true
    skipunavailable: true
    task:
      brand: ""
      description: |-
        Use this playbook to investigate and remediate a potential phishing incident. The playbook simultaneously engages with the user that triggered the incident, while investigating the incident itself.

        The final remediation tasks are always decided by a human analyst.
      id: dccd6b57-14cb-423e-8a4a-49bb524d268e
      iscommand: false
      name: Phishing Investigation - Generic v2
      playbookId: Phishing Investigation - Generic v2
      type: playbook
      version: -1
    taskid: dccd6b57-14cb-423e-8a4a-49bb524d268e
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 820,
          "y": 1240
        }
      }
  "6":
    id: "6"
    ignoreworker: false
    loop:
      exitCondition: ""
      iscommand: false
      max: 100
      wait: 1
    nexttasks:
      '#none#':
      - "9"
    note: false
    quietmode: 0
    scriptarguments:
      AutoIsolation:
        simple: "3"
      Email: {}
      FilePath:
        complex:
          accessor: Path
          root: File
      Hostname:
        complex:
          accessor: Hostname
          root: Endpoint
      MD5:
        complex:
          accessor: md5string
          root: incident
      SHA1:
        complex:
          accessor: sha1
          root: incident
      SHA256:
        complex:
          accessor: sha256
          root: incident
      UseD2:
        simple: "no"
    separatecontext: true
    skipunavailable: true
    task:
      brand: ""
      description: |-
        This playbook is triggered by a malware incident from an 'Endpoint' type integration. The playbook performs enrichment, detonation, and hunting within the organization, and remediation on the malware.
        Used sub-playbooks:
        - Endpoint Enrichment - Generic v2.1
        - Retrieve File from Endpoint - Generic
        - Detonate File - Generic
        - File Enrichment - Generic v2
        - Calculate Severity - Generic v2
        - Isolate Endpoint - Generic
        - Block Indicators - Generic v2
      id: b454b964-1d49-4aa3-8f1d-a1942c67e3d3
      iscommand: false
      name: Endpoint Malware Investigation - Generic
      playbookId: Endpoint Malware Investigation - Generic
      type: playbook
      version: -1
    taskid: b454b964-1d49-4aa3-8f1d-a1942c67e3d3
    timertriggers: []
    type: playbook
    view: |-
      {
        "position": {
          "x": 820,
          "y": 1730
        }
      }
  "7":
    id: "7"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "8"
      "yes":
      - "10"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      description: Would you like to use "Phishing Investigation - Generic v2 playbook?
      id: 90d8aa99-edb6-4772-8e78-b0e692dca95f
      iscommand: false
      name: Would you like to use "Phishing Investigation - Generic v2?
      type: condition
      version: -1
    taskid: 90d8aa99-edb6-4772-8e78-b0e692dca95f
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 450,
          "y": 920
        }
      }
  "8":
    id: "8"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "9"
      "yes":
      - "11"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      description: Would you like to use "Access Investigation - Generic" playbook?
      id: 661caf70-78d0-45c8-8855-a9cead5e64cd
      iscommand: false
      name: Would you like to use "Access Investigation - Generic" playbook?
      type: condition
      version: -1
    taskid: 661caf70-78d0-45c8-8855-a9cead5e64cd
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 450,
          "y": 1415
        }
      }
  "9":
    id: "9"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "19"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: Handled.Techniques
      stringify: {}
      value:
        simple: T1566
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: 27847884-c59d-4520-8d79-3e3313220c1d
      iscommand: false
      name: Set technique handled
      script: Set
      type: regular
      version: -1
    taskid: 27847884-c59d-4520-8d79-3e3313220c1d
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 450,
          "y": 1900
        }
      }
  "10":
    id: "10"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "5"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      id: d179b3c5-55a4-4ae9-8993-0009be78ddfe
      iscommand: false
      name: Deploy Cortex XSOAR Playbook – Phishing Investigation - Generic v2
      type: title
      version: -1
      description: ''
    taskid: d179b3c5-55a4-4ae9-8993-0009be78ddfe
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 820,
          "y": 1090
        }
      }
  "11":
    id: "11"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "6"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      id: e9dd57c0-56af-4845-8bb3-17a48f5fadd0
      iscommand: false
      name: Deploy Cortex XSOAR Playbook – Endpoint Malware Investigation - Generic
      type: title
      version: -1
      description: ''
    taskid: e9dd57c0-56af-4845-8bb3-17a48f5fadd0
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 820,
          "y": 1590
        }
      }
  "12":
    id: "12"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "1"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      id: ca4fa64d-0f08-415f-87c4-baa055805ff5
      iscommand: false
      name: Setup file blocking in Cortex XDR
      type: title
      version: -1
      description: ''
    taskid: ca4fa64d-0f08-415f-87c4-baa055805ff5
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 450,
          "y": -330
        }
      }
  "13":
    id: "13"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "2"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      id: 301ace9a-a00f-41e4-8f1c-eec88d21eb0f
      iscommand: false
      name: PAN-OS - Enforce Anti-Virus Best Practices Profile
      type: title
      version: -1
      description: ''
    taskid: 301ace9a-a00f-41e4-8f1c-eec88d21eb0f
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 450,
          "y": -20
        }
      }
  "14":
    id: "14"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "3"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      id: 28258f8a-0aa6-4520-839a-eb1a80b51646
      iscommand: false
      name: PAN-OS - Enforce WildFire Best Practices Profile
      type: title
      version: -1
      description: ''
    taskid: 28258f8a-0aa6-4520-839a-eb1a80b51646
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 450,
          "y": 300
        }
      }
  "15":
    id: "15"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "4"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      id: 6454dac8-a5eb-4ec7-8975-33e336ca1e3b
      iscommand: false
      name: Configure Malware Security Profile in Cortex XDR
      type: title
      version: -1
      description: ''
    taskid: 6454dac8-a5eb-4ec7-8975-33e336ca1e3b
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 450,
          "y": 610
        }
      }
  "16":
    id: "16"
    ignoreworker: false
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      id: 6bdf8c2f-37e1-4f4b-86d6-2a6cce71622e
      iscommand: false
      name: Done
      type: title
      version: -1
      description: ''
    taskid: 6bdf8c2f-37e1-4f4b-86d6-2a6cce71622e
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2270
        }
      }
  "17":
    id: "17"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "18"
      "yes":
      - "12"
    note: false
    quietmode: 0
    scriptarguments:
      brandname:
        simple: Cortex XDR - IR
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'
      id: 8f7ac68a-6290-460e-8e89-813de391d237
      iscommand: false
      name: Is Cortex XDR integration Enabled?
      script: IsIntegrationAvailable
      type: condition
      version: -1
    taskid: 8f7ac68a-6290-460e-8e89-813de391d237
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 450,
          "y": -675
        }
      }
  "18":
    id: "18"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "12"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      description: |
        Enable the Cortex XDR integration to follow this CoA.

        If needed - please contact your Palo Alto Networks account manager for future guidance and assistance.
      id: d8f9bf82-e8ce-4f39-8047-420de382b072
      iscommand: false
      name: Manual - Enable Cortex XDR integration
      type: regular
      version: -1
    taskid: d8f9bf82-e8ce-4f39-8047-420de382b072
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 850,
          "y": -500
        }
      }
  "19":
    continueonerror: true
    id: "19"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "16"
    note: false
    quietmode: 0
    scriptarguments:
      columns:
        simple: technique
      context_path:
        simple: Handled.Techniques
      grid_id:
        simple: handledtechniques
      keys: {}
      overwrite: {}
      sort_by: {}
      unpack_nested_elements: {}
    separatecontext: false
    skipunavailable: true
    task:
      brand: ""
      description: Creates a Grid table from items or key-value pairs.
      id: cb49f8d4-2fc7-44ae-857b-d56fa653dcd2
      iscommand: false
      name: Set grid field
      script: SetGridField
      type: regular
      version: -1
    taskid: cb49f8d4-2fc7-44ae-857b-d56fa653dcd2
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 450,
          "y": 2080
        }
      }
version: -1
view: |-
  {
    "linkLabelsPosition": {
      "7_8_#default#": 0.49,
      "8_9_#default#": 0.44
    },
    "paper": {
      "dimensions": {
        "height": 3165,
        "width": 780,
        "x": 450,
        "y": -830
      }
    }
  }
tests:
- No tests (auto formatted)
fromversion: 6.5.0