High School IntermediateModule I16Lesson 2 of 8

I16.2 Fake Phishing Triage Lab

Triage fictional suspicious messages using safe sender, routing, content, business-context, authentication, campaign, and user- interaction evidence without opening real links, attachments, files, accounts, or private messages.

Lesson Progress

Fake Phishing Triage Lab

High School IntermediateI16: Intermediate Defensive Labs • Lesson 2 of 8

25% complete

Readiness Check

Before You Start

0/5 ready

Professional Hook

A Click Does Not Automatically Mean an Account Was Compromised

One fictional user clicked a payroll-themed link but did not enter information. The message is still high-confidence malicious based on failed identity checks, an unrelated destination description, urgent credential pressure, and no approved campaign. However, credential disclosure and account takeover remain unconfirmed. Professional triage acts quickly without overstating impact.

Weak triage

Trust the display name, click to investigate, assume every interaction means compromise, reset everyone, block broadly, and close after message removal.

Professional triage

Preserve the report, validate identity and context, determine confirmed interaction, choose disposition, act proportionately, guide users, validate outcomes, and improve.

Objective 1

Define a fictional phishing-triage scope that identifies the message, recipients, reporting path, business context, approved evidence, privacy limits, owners, and required decisions.

Objective 2

Evaluate fictional sender identity, reply path, display name, message language, link text, attachment description, timing, authentication results, reporting history, and user activity without opening real suspicious content.

Objective 3

Distinguish fictional warning signs, direct observations, supported conclusions, alternate explanations, missing evidence, potential impact, confirmed impact, confidence, and disposition.

Objective 4

Coordinate fictional user guidance, mailbox review, identity review, message containment, supplier communication, case escalation, and recovery through the correct approved owners.

Objective 5

Create a portfolio-safe fictional phishing-triage package with an evidence register, message analysis, recipient-impact review, disposition, communications, validation, metrics, and improvement recommendations.

Why This Matters

Phishing Triage Protects People, Identity, Payments, and Trust

Fictional phishing reports may involve credentials, payment changes, document sharing, voice messages, delivery notices, internal campaigns, or authorized simulations. The analyst must decide what is directly supported, who interacted, which owners have authority, what guidance is safe, and how to prevent repeat exposure without disrupting legitimate communication.

Core Concept

Use the Sender–Request–Context–Interaction–Action Model

Sender

Which fictional display name, address, reply path, authenticated identity, sending service, routing, and known owner appear?

Request

Which fictional click, sign-in, reply, payment, attachment, download, data entry, or approval is requested?

Context

Does the fictional message match approved payroll, supplier, collaboration, identity, delivery, training, or internal communication records?

Interaction

Which fictional view, report, click, reply, open, data entry, approval, and no-action states are directly confirmed?

Action

Which fictional removal, guidance, identity review, supplier verification, monitoring, escalation, recovery, validation, and improvement are proportionate?

Key Vocabulary

Phishing Triage and Message-Evidence Terms

Phishing

A fictional social-engineering attempt that tries to influence a person into revealing information, visiting an unsafe destination, opening unsafe content, approving a request, or changing behavior.

Display name

The fictional visible sender name shown to the recipient, which may differ from the actual sending address or authenticated identity.

Sender address

The fictional mailbox address recorded as the message sender.

Reply path

The fictional address or route that receives replies and may differ from the visible sender.

Authentication result

A fictional defensive record describing whether approved email identity checks passed, failed, or were unavailable.

Header evidence

Fictional message-routing, identity, timing, and authentication information supplied for safe analysis without opening real content.

Link text

The fictional words displayed to the recipient for a hyperlink.

Destination description

A fictional safe description of where a link claims to go, without providing or opening a real suspicious destination.

Attachment description

A fictional safe summary of a file name, type, size, and claimed purpose without opening the file.

Urgency cue

Fictional language designed to pressure the recipient into acting quickly or avoiding normal verification.

Authority cue

Fictional language or branding that imitates a trusted leader, teacher, supplier, service, or organization.

Credential request

A fictional request for usernames, passwords, recovery codes, authentication approvals, or other access information.

User interaction

A fictional recorded action such as viewing, reporting, replying, clicking, opening, entering information, approving a prompt, or doing nothing.

Message disposition

A fictional decision such as benign, suspicious, malicious, duplicate, spam, test, business communication, or insufficient evidence.

Containment

A fictional approved action that limits additional exposure, such as removing a message, blocking a sender pattern, resetting access, or isolating a case.

User guidance

A fictional clear instruction telling recipients what is known, what not to do, how to report, what recovery steps apply, and when the next update will arrive.

Message Evidence

Eight Fictional Northbridge Messages

NBR-PHISH-01

Immediate payroll verification required

High-confidence malicious simulation

Sender

Payroll Support <payroll-help@fictional-mail.example>

Reply path

secure-update@fictional-reply.example

Audience

Twelve fictional employees

Language and request

Claims payroll access will be suspended within twenty minutes unless the recipient signs in.

Link evidence

Text says Review payroll account; destination description uses an unrelated fictional sign-in domain.

Attachment evidence

None

Authentication

Sender identity checks failed in the supplied fictional record.

Campaign or business history

No approved payroll campaign matches the subject, sender, timing, or message template.

User interaction

Nine users reported it; one fictional user clicked but did not enter information.

Evidence limit

No real credentials, domains, messages, or employee data are included.

NBR-PHISH-02

Updated classroom technology schedule

Likely benign approved communication

Sender

Technology Office <tech-office@northbridge.example>

Reply path

tech-office@northbridge.example

Audience

Fictional teachers

Language and request

Neutral announcement with no urgent action.

Link evidence

No link

Attachment evidence

One fictional PDF schedule from an approved internal sender; file not opened in the lab.

Authentication

Supplied fictional checks passed.

Campaign or business history

Matches an approved internal communication listed in the campaign register.

User interaction

No reports or suspicious activity.

Evidence limit

Passing identity checks does not prove every attachment is safe, so normal handling still applies.

NBR-PHISH-03

Shared document: Board planning notes

Suspicious pending owner validation

Sender

Document Service <share-notice@fictional-docs.example>

Reply path

no-reply@fictional-docs.example

Audience

Three fictional finance users

Language and request

Invites recipients to view a confidential document and asks them to sign in.

Link evidence

Displayed service name differs from the fictional destination description.

Attachment evidence

None

Authentication

Authentication results are incomplete.

Campaign or business history

No matching share appears in the approved collaboration register.

User interaction

One recipient viewed the message; no click is recorded.

Evidence limit

The message may represent a legitimate external share, but the current evidence does not support it.

NBR-PHISH-04

Supplier invoice correction

High-risk business email compromise simulation

Sender

Fictional Supplier Billing <billing@fictional-supplier.example>

Reply path

accounts-update@fictional-mail.example

Audience

Two fictional accounts-payable users

Language and request

Requests a bank-detail change before an invoice deadline.

Link evidence

No link

Attachment evidence

One fictional spreadsheet described as updated payment instructions; file not opened.

Authentication

Sender checks passed, but the reply path differs.

Campaign or business history

The supplier owner has no approved payment-change request.

User interaction

One user replied asking for clarification but shared no information.

Evidence limit

The source of the message is not proven to be the real supplier contact.

NBR-PHISH-05

Password expires today

Benign but communication-quality review needed

Sender

Identity Team <identity-alert@northbridge.example>

Reply path

identity-alert@northbridge.example

Audience

Forty fictional users

Language and request

Urgent but matches a documented internal expiration campaign.

Link evidence

No direct sign-in link; directs users to the normal saved portal.

Attachment evidence

None

Authentication

Supplied fictional checks passed.

Campaign or business history

Campaign ID and timing match the approved identity notification register.

User interaction

Two users reported it because of the urgency wording.

Evidence limit

The message may still create confusion because the tone resembles common phishing pressure.

NBR-PHISH-06

Voice message received

High-confidence malicious simulation

Sender

Messaging Notifications <voice-alert@fictional-messaging.example>

Reply path

no-reply@fictional-messaging.example

Audience

Six fictional users

Language and request

Short notification with a button labeled Play message.

Link evidence

Destination description is an unfamiliar fictional file-sharing location.

Attachment evidence

None

Authentication

One identity check failed and one result is unavailable.

Campaign or business history

No approved messaging service uses this sender or template.

User interaction

No user interaction is recorded.

Evidence limit

No real destination or message was opened.

NBR-PHISH-07

Security awareness test

Authorized simulation

Sender

Security Training <training@northbridge.example>

Reply path

training@northbridge.example

Audience

Fictional pilot group

Language and request

Contains common warning signs as part of an approved training exercise.

Link evidence

Destination description points to the approved fictional training platform.

Attachment evidence

None

Authentication

Supplied fictional checks passed.

Campaign or business history

Matches the approved awareness simulation register.

User interaction

User reports are expected and routed to the training team.

Evidence limit

The analyst still confirms campaign ownership before closing reports.

NBR-PHISH-08

Package delivery problem

High-confidence malicious simulation with user interaction

Sender

Delivery Updates <notice@fictional-delivery.example>

Reply path

support@fictional-delivery.example

Audience

Twenty fictional users

Language and request

Requests a small redelivery payment within one hour.

Link evidence

Displayed delivery brand does not match the fictional destination description.

Attachment evidence

None

Authentication

Sender authentication failed.

Campaign or business history

No organization-wide delivery campaign exists.

User interaction

Four users clicked; one entered a fictional email address but no password or payment data.

Evidence limit

The lab contains no real payment data, user data, or destination.

Triage Questions

Eight Questions before Final Disposition

Who appears to be sending the message?

Strong analysis

Record the fictional display name, sender address, reply path, authenticated identity, sending service, and known owner separately.

Weak analysis

Trust the display name or logo.

Reviewer question

Do the visible identity and technical identity agree?

What action is the message asking for?

Strong analysis

Identify the fictional click, reply, sign-in, attachment, payment, data entry, approval, download, or urgency request.

Weak analysis

Summarize the message as suspicious without identifying the requested behavior.

Reviewer question

What could happen if a recipient follows the request?

Does the message match approved business context?

Strong analysis

Compare the fictional campaign register, supplier owner, service owner, collaboration record, change calendar, and normal communication pattern.

Weak analysis

Assume an unfamiliar message is malicious or a familiar brand is safe.

Reviewer question

Which owner can confirm whether the communication was expected?

What do the authentication and routing records show?

Strong analysis

Document fictional pass, fail, unavailable, forwarding, reply-path, routing, and source limitations.

Weak analysis

Treat one passed check as proof of legitimacy.

Reviewer question

Can the evidence support identity, integrity, or only partial routing context?

What did recipients do?

Strong analysis

Record fictional view, report, reply, click, open, data entry, approval, and no-action states with timestamps and evidence limits.

Weak analysis

Assume a click means credentials were entered.

Reviewer question

Which interactions are directly confirmed?

What is the message disposition?

Strong analysis

Choose fictional benign, suspicious, malicious, duplicate, spam, authorized simulation, business communication, or insufficient evidence with rationale and confidence.

Weak analysis

Use only High, Medium, or Low severity as the final conclusion.

Reviewer question

What exact evidence supports the disposition?

Which actions are proportionate?

Strong analysis

Choose fictional message removal, sender review, mailbox search, user guidance, identity review, supplier verification, case escalation, monitoring, or no new action.

Weak analysis

Reset every user or block an entire service automatically.

Reviewer question

What is the least disruptive action that reduces risk and uncertainty?

How will the outcome be validated?

Strong analysis

Confirm fictional message removal, identity state, user impact, supplier verification, reporting completion, recurrence, detection quality, and residual risk.

Weak analysis

Close the case when no new reports arrive.

Reviewer question

What evidence proves the defensive objective was achieved?

Triage Workflow

Eight Steps from Report to Improvement

1

Receive and preserve the report

Record the fictional reporter, message identifier, recipient group, time, claimed sender, requested action, and approved handling limits without opening unsafe content.

Output: Triage intake record.

2

Validate message identity and routing

Compare fictional display name, sender address, reply path, authentication results, sending service, routing, and known communication owner.

Output: Sender and routing assessment.

3

Review content and business context

Analyze fictional urgency, authority, link description, attachment description, payment or credential request, campaign register, supplier context, and expected business process.

Output: Content and context matrix.

4

Assess recipient interaction

Determine fictional view, reply, click, open, data entry, approval, report, and no-action states using approved evidence.

Output: User-impact record.

5

Choose disposition and priority

Document fictional benign, suspicious, malicious, simulation, duplicate, spam, business communication, or insufficient evidence with confidence and limits.

Output: Disposition and priority decision.

6

Coordinate proportionate actions

Assign fictional mailbox, identity, service, supplier, user-support, communication, case, risk, or response actions with authority, deadlines, and rollback.

Output: Action and escalation plan.

7

Communicate and validate

Send fictional user guidance, owner requests, supplier verification, technical updates, leadership summaries, and confirm removal, recovery, source health, and residual risk.

Output: Communication and validation record.

8

Close and improve

Complete fictional peer review, closure criteria, detection feedback, reporting metrics, template changes, training, supplier process, and lessons learned.

Output: Closure and improvement package.

User Guidance

Fictional Guidance by Confirmed Interaction

User who only viewed or reported

Guidance

Thank you for reporting the fictional message. Do not reply, click, open, or forward it. No additional account action is required unless the security team contacts you.

Validation

Confirm the report was received and the message was removed from the mailbox if authorized.

User who clicked but entered nothing

Guidance

Stop interacting with the fictional page, close it, and report the approximate time. Do not revisit it. The identity team will review approved sign-in evidence.

Validation

Confirm the user entered no information and review identity records for unusual activity.

User who replied without sharing sensitive data

Guidance

Do not continue the conversation. Preserve the reply record through the approved reporting process and wait for verified supplier or owner guidance.

Validation

Confirm no sensitive information, payment change, attachment, or credential was shared.

User who entered fictional credentials in the lab

Guidance

Use the approved fictional recovery workflow immediately and follow identity-owner instructions. Never reuse or disclose real credentials in training.

Validation

Confirm access recovery, active-session review, approved reset completion, and monitoring.

User who approved a fictional sign-in prompt

Guidance

Report the approval immediately through the approved process and follow identity-owner recovery instructions.

Validation

Confirm session review, access state, recovery, and any affected case actions.

General recipient group

Guidance

The fictional message is under review. Do not interact with it. Use the normal reporting channel and wait for the next official update.

Validation

Confirm the communication reached the correct audience and does not reveal unnecessary case details.

Fake Dashboard

Fake Northbridge Phishing Triage Dashboard

Training dashboard for fictional message evidence only.

Messages reviewed

8

The set includes malicious simulations, suspicious messages, benign communication, and an authorized training exercise.

Confirmed user clicks

5

Clicks are confirmed across two fictional messages, while credential and payment disclosure remain unconfirmed.

Confirmed account compromise

0

The fictional evidence supports targeted identity review but no confirmed account takeover.

Fake SOC Alert

Payroll-Themed Message Triggered One Confirmed Click

Source: Fake Northbridge Mail Defense Console • Time: 10:18 PM

High Severity
A fictional payroll message failed sender checks, used an unrelated sign-in destination description, applied urgent account-suspension pressure, and did not match an approved campaign. One user clicked but did not enter information.
Defensive recommendation: Remove the message, identify affected recipients, review the clicked user's approved identity evidence, provide targeted guidance, preserve that compromise is unconfirmed, update detection, and validate whether related messages or activity exist.

Fake Log Panel

Fake Northbridge Message-Triage Timeline

training-log-viewer.log
09:00 REPORT payroll-message='received'
09:04 AUTH sender-check='failed'
09:08 CONTEXT approved-campaign='not found'
09:12 LINK destination-match='false'
09:16 USERS reports='9'
09:20 INTERACTION click='1'
09:24 INTERACTION credential-entry='not confirmed'
09:28 ACTION remove-message='approved'
09:32 ACTION identity-review='opened'
09:36 GUIDANCE clicked-user='sent'
09:40 SEARCH related-messages='in progress'
09:44 CASE disposition='malicious simulation'
09:48 LIMIT account-compromise='unconfirmed'
09:52 DETECTION feedback='opened'
09:56 VALIDATE new-reports='monitoring'
10:00 CLOSE criteria='pending identity review'

Training note: this is fake data for defensive analysis practice only.

Findings Matrix

Six Fictional Findings with Confidence and Limits

NBR-PH-F01High

The fictional payroll message is a high-confidence malicious simulation requiring message removal and targeted user follow-up.

Evidence support

Failed sender checks, unrelated destination description, urgent credential pressure, no approved campaign, multiple reports, and one confirmed click.

Alternate explanation

A poorly configured legitimate payroll vendor is possible but not supported by the current evidence.

Impact statement

One click is confirmed; credential entry and account compromise are not confirmed.

Next action

Remove the message, review the clicked user's identity evidence, provide guidance, and improve detection.

NBR-PH-F02High

The fictional classroom schedule message is likely an approved internal communication.

Evidence support

Matching internal sender, passed checks, approved campaign record, neutral language, and no suspicious interaction.

Alternate explanation

An approved sender could still distribute an unsafe file if its account or workflow were compromised.

Impact statement

No harmful user action or security impact is supported.

Next action

Close as benign after normal attachment-handling confirmation.

NBR-PH-F03Medium-High

The fictional shared-document message should remain suspicious pending owner validation.

Evidence support

Destination mismatch, incomplete authentication, no approved share record, confidential lure, and no confirmed click.

Alternate explanation

A legitimate external partner may have initiated an unregistered share.

Impact statement

Potential credential risk exists; user interaction is not confirmed.

Next action

Verify with the collaboration owner and maintain targeted monitoring.

NBR-PH-F04High

The fictional supplier invoice message is a high-risk business email compromise simulation.

Evidence support

Payment-change request, mismatched reply path, no approved supplier request, attachment lure, and business deadline pressure.

Alternate explanation

The supplier may have changed its billing process without proper notification.

Impact statement

A user replied, but no payment or sensitive information was shared.

Next action

Verify through the known supplier channel, remove the message, and review payment-change controls.

NBR-PH-F05High

The fictional password-expiration message is benign but should be improved because its urgency resembles phishing pressure.

Evidence support

Passed checks, approved campaign ID, expected sender, no direct sign-in link, and matching schedule.

Alternate explanation

A copied template could imitate the approved campaign, so identity evidence remains necessary.

Impact statement

No security impact is supported; user confusion is confirmed through reports.

Next action

Close as benign and improve wording, branding, and reporting guidance.

NBR-PH-F06High

The fictional package-delivery message requires targeted user-impact review because several clicks occurred.

Evidence support

Failed authentication, destination mismatch, payment request, no approved campaign, four clicks, and one fictional email entry.

Alternate explanation

A legitimate delivery notice is possible but contradicted by the supplied identity and context evidence.

Impact statement

Clicks and one email entry are confirmed; password or payment disclosure is not confirmed.

Next action

Remove the message, guide recipients, review the interacting identity, and monitor for related activity.

Analyze the Evidence

Did the Payroll Link Click Confirm Account Compromise?

The fictional payroll message failed sender checks.
The fictional destination description did not match the claimed payroll service.
No approved payroll campaign matched the message.
One fictional user clicked the link.
The user reports entering no information.
No supplied identity evidence confirms account takeover.

Which conclusion is strongest?

Common Mistakes

Mistakes That Weaken Fictional Phishing Triage

Opening or clicking real suspicious links, attachments, files, accounts, or messages during analysis.
Trusting a fictional display name, logo, familiar brand, or passed authentication check by itself.
Treating one failed check as proof of malicious intent without context.
Assuming a click means credentials, payment data, or confidential information were entered.
Assuming no click means no risk or no required containment.
Reporting a possible credential compromise as confirmed account takeover.
Resetting every recipient account without evidence or proportionality.
Blocking an entire legitimate service because one message used a similar brand.
Ignoring business email compromise risks because no link is present.
Opening a fictional attachment instead of analyzing its supplied safe description.
Failing to verify payment, supplier, collaboration, payroll, or identity requests through known approved channels.
Sending vague user guidance that does not explain what not to do or what happens next.
Closing the case when messages are removed without validating user interaction, identity state, detection, and residual risk.
Using or exposing any real credentials, employee data, school records, private messages, email addresses, supplier records, incident evidence, or confidential organizational information.

Safe Practice Lab

Build the Northbridge Fake Phishing Triage Package

Your fictional assignment

Message Evidence, Disposition, User Impact, Actions, and Validation

Use only the supplied fictional Northbridge message records to create a complete, safe, evidence-limited phishing-triage package.

Required deliverables

  1. Triage intake record with reporter, recipient group, message identifier, time, claimed sender, requested action, and safety limits.
  2. Sender, reply-path, authentication, routing, content, business-context, campaign, and link or attachment evidence matrix.
  3. User-interaction register with view, report, click, reply, open, data entry, approval, and no-action states.
  4. Message disposition with evidence, confidence, alternatives, limitations, potential impact, and confirmed impact.
  5. Mailbox, identity, supplier, service, case, user-support, communication, and monitoring action plan.
  6. Audience-specific user guidance and owner communications.
  7. Validation, closure criteria, detection feedback, metrics, and improvement actions.
  8. Technical summary, leadership summary, reflection, and portfolio-safety statement.
Complete the lab only with fictional evidence displayed on this page. Do not open real suspicious links, attachments, files, accounts, messages, or prompts. Never use real credentials, employee data, school records, email addresses, supplier records, incident evidence, or confidential organizational information.

Scenario Decision Lab

A User Clicked the Fictional Payroll Link but Entered Nothing

The fictional message is high-confidence malicious, but no credential entry, sign-in approval, or account takeover is confirmed.

Scenario Decision Lab

A Supplier Invoice Requests New Payment Details

The fictional sender checks passed, but the reply path differs, no approved payment-change request exists, and the message pressures the user to act before a deadline.

Defender Habits

Fake Phishing Triage Checklist

Check Your Understanding

I16.2 Mini Quiz: Fake Phishing Triage Lab

Choose your answers first. Explanations appear only after submission.

1. What is the safest first step when receiving a fictional suspicious-message report?

2. What does a fictional failed email authentication result prove?

3. How should the fictional payroll message be handled?

4. Why is the fictional supplier invoice message high risk even without a link?

5. What should happen after a fictional user clicks but enters no information?

6. Why might a benign fictional password-expiration message still require improvement?

7. What makes a fictional phishing disposition defensible?

Portfolio Prompt

Portfolio Prompt

Create a fictional Fake Phishing Triage Package for Northbridge. Include the intake record, message and header evidence matrix, sender and reply-path review, authentication and routing assessment, business-context check, user-interaction register, disposition, priority, findings, owner and escalation map, containment plan, user guidance, supplier verification, identity review, validation, closure criteria, metrics, detection feedback, leadership summary, technical summary, reflection, and a portfolio-safety statement.

Use only fictional messages, senders, recipients, addresses, destinations, attachments, campaigns, interactions, systems, owners, actions, and outcomes.
Never include or interact with real suspicious links, attachments, files, accounts, messages, prompts, credentials, or private information.
Do not treat display names, authentication results, clicks, replies, urgency, brands, or absent reports as automatic proof.
Show how a message can be high-confidence malicious while account compromise remains unconfirmed.

Key Takeaways

What You Should Remember

1.Phishing triage must remain safe and should never require opening real suspicious content.
2.Display names, sender addresses, reply paths, authentication, routing, and business context should be evaluated separately.
3.A click, reply, or report does not automatically prove credential disclosure or account compromise.
4.Business email compromise may use payment changes and replies without links.
5.Disposition, user impact, and incident status are different decisions.
6.User guidance should match the confirmed interaction and explain the next step.
7.Portfolio artifacts should use fully fictional evidence and never expose real messages, credentials, or private organizational data.

Navigation

Continue Module I16