Phishing
A fictional social-engineering attempt that tries to influence a person into revealing information, visiting an unsafe destination, opening unsafe content, approving a request, or changing behavior.
Triage fictional suspicious messages using safe sender, routing, content, business-context, authentication, campaign, and user- interaction evidence without opening real links, attachments, files, accounts, or private messages.
Lesson Progress
High School Intermediate • I16: Intermediate Defensive Labs • Lesson 2 of 8
Readiness Check
0/5 ready
Professional Hook
One fictional user clicked a payroll-themed link but did not enter information. The message is still high-confidence malicious based on failed identity checks, an unrelated destination description, urgent credential pressure, and no approved campaign. However, credential disclosure and account takeover remain unconfirmed. Professional triage acts quickly without overstating impact.
Weak triage
Trust the display name, click to investigate, assume every interaction means compromise, reset everyone, block broadly, and close after message removal.
Professional triage
Preserve the report, validate identity and context, determine confirmed interaction, choose disposition, act proportionately, guide users, validate outcomes, and improve.
Objective 1
Define a fictional phishing-triage scope that identifies the message, recipients, reporting path, business context, approved evidence, privacy limits, owners, and required decisions.
Objective 2
Evaluate fictional sender identity, reply path, display name, message language, link text, attachment description, timing, authentication results, reporting history, and user activity without opening real suspicious content.
Objective 3
Distinguish fictional warning signs, direct observations, supported conclusions, alternate explanations, missing evidence, potential impact, confirmed impact, confidence, and disposition.
Objective 4
Coordinate fictional user guidance, mailbox review, identity review, message containment, supplier communication, case escalation, and recovery through the correct approved owners.
Objective 5
Create a portfolio-safe fictional phishing-triage package with an evidence register, message analysis, recipient-impact review, disposition, communications, validation, metrics, and improvement recommendations.
Why This Matters
Fictional phishing reports may involve credentials, payment changes, document sharing, voice messages, delivery notices, internal campaigns, or authorized simulations. The analyst must decide what is directly supported, who interacted, which owners have authority, what guidance is safe, and how to prevent repeat exposure without disrupting legitimate communication.
Core Concept
Sender
Which fictional display name, address, reply path, authenticated identity, sending service, routing, and known owner appear?
Request
Which fictional click, sign-in, reply, payment, attachment, download, data entry, or approval is requested?
Context
Does the fictional message match approved payroll, supplier, collaboration, identity, delivery, training, or internal communication records?
Interaction
Which fictional view, report, click, reply, open, data entry, approval, and no-action states are directly confirmed?
Action
Which fictional removal, guidance, identity review, supplier verification, monitoring, escalation, recovery, validation, and improvement are proportionate?
Key Vocabulary
A fictional social-engineering attempt that tries to influence a person into revealing information, visiting an unsafe destination, opening unsafe content, approving a request, or changing behavior.
The fictional visible sender name shown to the recipient, which may differ from the actual sending address or authenticated identity.
The fictional mailbox address recorded as the message sender.
The fictional address or route that receives replies and may differ from the visible sender.
A fictional defensive record describing whether approved email identity checks passed, failed, or were unavailable.
Fictional message-routing, identity, timing, and authentication information supplied for safe analysis without opening real content.
The fictional words displayed to the recipient for a hyperlink.
A fictional safe description of where a link claims to go, without providing or opening a real suspicious destination.
A fictional safe summary of a file name, type, size, and claimed purpose without opening the file.
Fictional language designed to pressure the recipient into acting quickly or avoiding normal verification.
Fictional language or branding that imitates a trusted leader, teacher, supplier, service, or organization.
A fictional request for usernames, passwords, recovery codes, authentication approvals, or other access information.
A fictional recorded action such as viewing, reporting, replying, clicking, opening, entering information, approving a prompt, or doing nothing.
A fictional decision such as benign, suspicious, malicious, duplicate, spam, test, business communication, or insufficient evidence.
A fictional approved action that limits additional exposure, such as removing a message, blocking a sender pattern, resetting access, or isolating a case.
A fictional clear instruction telling recipients what is known, what not to do, how to report, what recovery steps apply, and when the next update will arrive.
Message Evidence
Sender
Payroll Support <payroll-help@fictional-mail.example>
Reply path
secure-update@fictional-reply.example
Audience
Twelve fictional employees
Language and request
Claims payroll access will be suspended within twenty minutes unless the recipient signs in.
Link evidence
Text says Review payroll account; destination description uses an unrelated fictional sign-in domain.
Attachment evidence
None
Authentication
Sender identity checks failed in the supplied fictional record.
Campaign or business history
No approved payroll campaign matches the subject, sender, timing, or message template.
User interaction
Nine users reported it; one fictional user clicked but did not enter information.
Evidence limit
No real credentials, domains, messages, or employee data are included.
Sender
Technology Office <tech-office@northbridge.example>
Reply path
tech-office@northbridge.example
Audience
Fictional teachers
Language and request
Neutral announcement with no urgent action.
Link evidence
No link
Attachment evidence
One fictional PDF schedule from an approved internal sender; file not opened in the lab.
Authentication
Supplied fictional checks passed.
Campaign or business history
Matches an approved internal communication listed in the campaign register.
User interaction
No reports or suspicious activity.
Evidence limit
Passing identity checks does not prove every attachment is safe, so normal handling still applies.
Sender
Document Service <share-notice@fictional-docs.example>
Reply path
no-reply@fictional-docs.example
Audience
Three fictional finance users
Language and request
Invites recipients to view a confidential document and asks them to sign in.
Link evidence
Displayed service name differs from the fictional destination description.
Attachment evidence
None
Authentication
Authentication results are incomplete.
Campaign or business history
No matching share appears in the approved collaboration register.
User interaction
One recipient viewed the message; no click is recorded.
Evidence limit
The message may represent a legitimate external share, but the current evidence does not support it.
Sender
Fictional Supplier Billing <billing@fictional-supplier.example>
Reply path
accounts-update@fictional-mail.example
Audience
Two fictional accounts-payable users
Language and request
Requests a bank-detail change before an invoice deadline.
Link evidence
No link
Attachment evidence
One fictional spreadsheet described as updated payment instructions; file not opened.
Authentication
Sender checks passed, but the reply path differs.
Campaign or business history
The supplier owner has no approved payment-change request.
User interaction
One user replied asking for clarification but shared no information.
Evidence limit
The source of the message is not proven to be the real supplier contact.
Sender
Identity Team <identity-alert@northbridge.example>
Reply path
identity-alert@northbridge.example
Audience
Forty fictional users
Language and request
Urgent but matches a documented internal expiration campaign.
Link evidence
No direct sign-in link; directs users to the normal saved portal.
Attachment evidence
None
Authentication
Supplied fictional checks passed.
Campaign or business history
Campaign ID and timing match the approved identity notification register.
User interaction
Two users reported it because of the urgency wording.
Evidence limit
The message may still create confusion because the tone resembles common phishing pressure.
Sender
Messaging Notifications <voice-alert@fictional-messaging.example>
Reply path
no-reply@fictional-messaging.example
Audience
Six fictional users
Language and request
Short notification with a button labeled Play message.
Link evidence
Destination description is an unfamiliar fictional file-sharing location.
Attachment evidence
None
Authentication
One identity check failed and one result is unavailable.
Campaign or business history
No approved messaging service uses this sender or template.
User interaction
No user interaction is recorded.
Evidence limit
No real destination or message was opened.
Sender
Security Training <training@northbridge.example>
Reply path
training@northbridge.example
Audience
Fictional pilot group
Language and request
Contains common warning signs as part of an approved training exercise.
Link evidence
Destination description points to the approved fictional training platform.
Attachment evidence
None
Authentication
Supplied fictional checks passed.
Campaign or business history
Matches the approved awareness simulation register.
User interaction
User reports are expected and routed to the training team.
Evidence limit
The analyst still confirms campaign ownership before closing reports.
Sender
Delivery Updates <notice@fictional-delivery.example>
Reply path
support@fictional-delivery.example
Audience
Twenty fictional users
Language and request
Requests a small redelivery payment within one hour.
Link evidence
Displayed delivery brand does not match the fictional destination description.
Attachment evidence
None
Authentication
Sender authentication failed.
Campaign or business history
No organization-wide delivery campaign exists.
User interaction
Four users clicked; one entered a fictional email address but no password or payment data.
Evidence limit
The lab contains no real payment data, user data, or destination.
Triage Questions
Strong analysis
Record the fictional display name, sender address, reply path, authenticated identity, sending service, and known owner separately.
Weak analysis
Trust the display name or logo.
Reviewer question
Do the visible identity and technical identity agree?
Strong analysis
Identify the fictional click, reply, sign-in, attachment, payment, data entry, approval, download, or urgency request.
Weak analysis
Summarize the message as suspicious without identifying the requested behavior.
Reviewer question
What could happen if a recipient follows the request?
Strong analysis
Compare the fictional campaign register, supplier owner, service owner, collaboration record, change calendar, and normal communication pattern.
Weak analysis
Assume an unfamiliar message is malicious or a familiar brand is safe.
Reviewer question
Which owner can confirm whether the communication was expected?
Strong analysis
Document fictional pass, fail, unavailable, forwarding, reply-path, routing, and source limitations.
Weak analysis
Treat one passed check as proof of legitimacy.
Reviewer question
Can the evidence support identity, integrity, or only partial routing context?
Strong analysis
Record fictional view, report, reply, click, open, data entry, approval, and no-action states with timestamps and evidence limits.
Weak analysis
Assume a click means credentials were entered.
Reviewer question
Which interactions are directly confirmed?
Strong analysis
Choose fictional benign, suspicious, malicious, duplicate, spam, authorized simulation, business communication, or insufficient evidence with rationale and confidence.
Weak analysis
Use only High, Medium, or Low severity as the final conclusion.
Reviewer question
What exact evidence supports the disposition?
Strong analysis
Choose fictional message removal, sender review, mailbox search, user guidance, identity review, supplier verification, case escalation, monitoring, or no new action.
Weak analysis
Reset every user or block an entire service automatically.
Reviewer question
What is the least disruptive action that reduces risk and uncertainty?
Strong analysis
Confirm fictional message removal, identity state, user impact, supplier verification, reporting completion, recurrence, detection quality, and residual risk.
Weak analysis
Close the case when no new reports arrive.
Reviewer question
What evidence proves the defensive objective was achieved?
Triage Workflow
Record the fictional reporter, message identifier, recipient group, time, claimed sender, requested action, and approved handling limits without opening unsafe content.
Output: Triage intake record.
Compare fictional display name, sender address, reply path, authentication results, sending service, routing, and known communication owner.
Output: Sender and routing assessment.
Analyze fictional urgency, authority, link description, attachment description, payment or credential request, campaign register, supplier context, and expected business process.
Output: Content and context matrix.
Determine fictional view, reply, click, open, data entry, approval, report, and no-action states using approved evidence.
Output: User-impact record.
Document fictional benign, suspicious, malicious, simulation, duplicate, spam, business communication, or insufficient evidence with confidence and limits.
Output: Disposition and priority decision.
Assign fictional mailbox, identity, service, supplier, user-support, communication, case, risk, or response actions with authority, deadlines, and rollback.
Output: Action and escalation plan.
Send fictional user guidance, owner requests, supplier verification, technical updates, leadership summaries, and confirm removal, recovery, source health, and residual risk.
Output: Communication and validation record.
Complete fictional peer review, closure criteria, detection feedback, reporting metrics, template changes, training, supplier process, and lessons learned.
Output: Closure and improvement package.
User Guidance
Guidance
Thank you for reporting the fictional message. Do not reply, click, open, or forward it. No additional account action is required unless the security team contacts you.
Validation
Confirm the report was received and the message was removed from the mailbox if authorized.
Guidance
Stop interacting with the fictional page, close it, and report the approximate time. Do not revisit it. The identity team will review approved sign-in evidence.
Validation
Confirm the user entered no information and review identity records for unusual activity.
Guidance
Do not continue the conversation. Preserve the reply record through the approved reporting process and wait for verified supplier or owner guidance.
Validation
Confirm no sensitive information, payment change, attachment, or credential was shared.
Guidance
Use the approved fictional recovery workflow immediately and follow identity-owner instructions. Never reuse or disclose real credentials in training.
Validation
Confirm access recovery, active-session review, approved reset completion, and monitoring.
Guidance
Report the approval immediately through the approved process and follow identity-owner recovery instructions.
Validation
Confirm session review, access state, recovery, and any affected case actions.
Guidance
The fictional message is under review. Do not interact with it. Use the normal reporting channel and wait for the next official update.
Validation
Confirm the communication reached the correct audience and does not reveal unnecessary case details.
Fake Dashboard
Training dashboard for fictional message evidence only.
Messages reviewed
8
The set includes malicious simulations, suspicious messages, benign communication, and an authorized training exercise.
Confirmed user clicks
5
Clicks are confirmed across two fictional messages, while credential and payment disclosure remain unconfirmed.
Confirmed account compromise
0
The fictional evidence supports targeted identity review but no confirmed account takeover.
Fake SOC Alert
Source: Fake Northbridge Mail Defense Console • Time: 10:18 PM
Fake Log Panel
09:00 REPORT payroll-message='received' 09:04 AUTH sender-check='failed' 09:08 CONTEXT approved-campaign='not found' 09:12 LINK destination-match='false' 09:16 USERS reports='9' 09:20 INTERACTION click='1' 09:24 INTERACTION credential-entry='not confirmed' 09:28 ACTION remove-message='approved' 09:32 ACTION identity-review='opened' 09:36 GUIDANCE clicked-user='sent' 09:40 SEARCH related-messages='in progress' 09:44 CASE disposition='malicious simulation' 09:48 LIMIT account-compromise='unconfirmed' 09:52 DETECTION feedback='opened' 09:56 VALIDATE new-reports='monitoring' 10:00 CLOSE criteria='pending identity review'
Training note: this is fake data for defensive analysis practice only.
Findings Matrix
Evidence support
Failed sender checks, unrelated destination description, urgent credential pressure, no approved campaign, multiple reports, and one confirmed click.
Alternate explanation
A poorly configured legitimate payroll vendor is possible but not supported by the current evidence.
Impact statement
One click is confirmed; credential entry and account compromise are not confirmed.
Next action
Remove the message, review the clicked user's identity evidence, provide guidance, and improve detection.
Evidence support
Matching internal sender, passed checks, approved campaign record, neutral language, and no suspicious interaction.
Alternate explanation
An approved sender could still distribute an unsafe file if its account or workflow were compromised.
Impact statement
No harmful user action or security impact is supported.
Next action
Close as benign after normal attachment-handling confirmation.
Evidence support
Destination mismatch, incomplete authentication, no approved share record, confidential lure, and no confirmed click.
Alternate explanation
A legitimate external partner may have initiated an unregistered share.
Impact statement
Potential credential risk exists; user interaction is not confirmed.
Next action
Verify with the collaboration owner and maintain targeted monitoring.
Evidence support
Payment-change request, mismatched reply path, no approved supplier request, attachment lure, and business deadline pressure.
Alternate explanation
The supplier may have changed its billing process without proper notification.
Impact statement
A user replied, but no payment or sensitive information was shared.
Next action
Verify through the known supplier channel, remove the message, and review payment-change controls.
Evidence support
Passed checks, approved campaign ID, expected sender, no direct sign-in link, and matching schedule.
Alternate explanation
A copied template could imitate the approved campaign, so identity evidence remains necessary.
Impact statement
No security impact is supported; user confusion is confirmed through reports.
Next action
Close as benign and improve wording, branding, and reporting guidance.
Evidence support
Failed authentication, destination mismatch, payment request, no approved campaign, four clicks, and one fictional email entry.
Alternate explanation
A legitimate delivery notice is possible but contradicted by the supplied identity and context evidence.
Impact statement
Clicks and one email entry are confirmed; password or payment disclosure is not confirmed.
Next action
Remove the message, guide recipients, review the interacting identity, and monitor for related activity.
Analyze the Evidence
Common Mistakes
Safe Practice Lab
Your fictional assignment
Use only the supplied fictional Northbridge message records to create a complete, safe, evidence-limited phishing-triage package.
Required deliverables
Scenario Decision Lab
The fictional message is high-confidence malicious, but no credential entry, sign-in approval, or account takeover is confirmed.
Scenario Decision Lab
The fictional sender checks passed, but the reply path differs, no approved payment-change request exists, and the message pressures the user to act before a deadline.
Defender Habits
Check Your Understanding
Choose your answers first. Explanations appear only after submission.
Portfolio Prompt
Create a fictional Fake Phishing Triage Package for Northbridge. Include the intake record, message and header evidence matrix, sender and reply-path review, authentication and routing assessment, business-context check, user-interaction register, disposition, priority, findings, owner and escalation map, containment plan, user guidance, supplier verification, identity review, validation, closure criteria, metrics, detection feedback, leadership summary, technical summary, reflection, and a portfolio-safety statement.
Key Takeaways
Navigation