Back to Playbooksv1.0.0
Phishing
Comprehensive incident response playbook for handling phishing attacks targeting organizational users via email, SMS, or other messaging platforms. Covers identification and analysis of phishing messages, email header forensics, URL and attachment inspection, credential compromise assessment, containment through mailbox quarantine and email filtering rules, eradication of malicious content, recovery including password resets and session revocation, and post-incident improvements to user awareness training. Based on the NIST Computer Security Incident Handling Guide (SP 800-61).
This playbook follows the NIST Incident Response Framework with 7 phases and 14 total steps.
Response Phases
Click a phase to view its steps, or click a step to view its flowchart