H3AD-REF / PLAYBOOKS / BEC PHISHING RESPONSE

BEC & Phishing Response.
Verify Before You Wire, Every Time.

A static process reference: the sources a BEC or phishing case typically comes in through, the triage steps that separate a targeted user from a compromised mailbox, the true and false positive indicators that keep the queue honest, and the escalation and containment actions once a case is confirmed real. Not a substitute for an org's own IR plan or legal counsel, just the reference. For working an active case, see PHISHOPS; for header/SPF/DKIM/DMARC analysis, see MAILSCOPE.

Alert & Report Overview

A BEC or phishing case rarely starts from one clean signal. It shows up through several different channels, and each one implies a slightly different starting point for the investigation.

Common Trigger Sources [T1566 Phishing]

User-reported suspicious email
├── An employee forwards or flags a message through the phish-report button or a support ticket
    // still the most common entry point, and often the fastest signal available

Mail gateway / SEG detection
├── The secure email gateway flags a message on spoofing, malicious link, or malicious attachment signatures
    // automated detection buys time, it doesn't replace a header review

Unusual mailbox rule creation alert
├── A rule engine or M365/Google Workspace alert fires on a newly created forwarding or hide-from-inbox rule
    A strong early signal of account compromise, not just a phishing attempt

Wire transfer request flagged by finance
├── A finance approval workflow flags an unusual or out-of-cycle payment request
    // often the first sign anyone catches on a BEC that's already partway through

New mail-forwarding rule added to a mailbox
├── Surfaced through mailbox audit logging rather than a user report
    // this one is frequently found only in retrospect, after the fact

Executive impersonation report ("CEO fraud")
├── A user reports a request that appears to come from a senior leader, usually urgent and out of the ordinary
    // authority plus urgency, the pattern that defines the whole category

Initial Triage Steps

The order matters. Evidence handling comes before analysis, and account-compromise checks come before you decide this is "just" a phishing report.

Triage Steps, In Order

1. Preserve the original message with full headers
├── Get the raw .eml/.msg file or the complete header text directly from the mailbox
└── Don't let the user forward it — forwarding strips or rewrites the headers you need
    // this is the evidence the rest of the case depends on

2. Check sender authentication results
├── Review SPF, DKIM, and DMARC pass/fail on the original message
└── Check the sending domain for lookalikes: character substitution, an added hyphen, a similar-looking TLD
    // authentication failures alone don't prove malice, but they narrow the field fast

3. Rule out account compromise, not just targeting
├── Check for new mailbox forwarding rules, new inbox rules, and recent sign-ins
└── Flag any sign-in from an unfamiliar location or ASN
    // a targeted user and a compromised mailbox need very different responses

4. Identify exactly what was requested
├── A wire transfer, gift cards, a credential-harvesting link, or a malicious attachment
    // the ask drives urgency more than the lure itself does

5. Check the blast radius
├── Search for the same or a similar message across other mailboxes
    // one report is rarely the full picture

True Positive Indicators

Signals that point to a real attempt in progress, not a false alarm or an internal test.

TRUE POSITIVE

Authentication Failure Or Lookalike Domain

The sending domain doesn't hold up under a second look
The sender domain fails SPF, DKIM, or DMARC, or it's a newly registered or lookalike domain built to pass a glance. A domain that's a week old with no prior sending history is rarely legitimate.
TRUE POSITIVE

Urgency Plus Authority Plus A Financial Ask

The core BEC pattern, present in nearly every real case
Pressure to act fast, framed as coming from someone senior, tied to moving money or data. When all three show up together, treat the message as malicious until proven otherwise.
TRUE POSITIVE

Reply-To Differs From The Visible From Address

A common BEC header manipulation technique
The name and address shown to the user look right, but replies route somewhere else entirely. This single header mismatch is one of the most reliable tells in the category.
TRUE POSITIVE

An Unexplained New Mailbox Rule

Appeared around the same time as the report
A forwarding rule, a hide-from-inbox rule, or an auto-delete rule that the user didn't create and can't explain. This shifts the case from phishing attempt to likely account compromise.
TRUE POSITIVE

Impossible Travel Or An Unfamiliar ASN

Sign-in activity that doesn't match the user's normal pattern
A sign-in from a country or ASN the account has never used, especially in the hours right before the suspicious message was sent, is a strong indicator the mailbox itself was the attacker's platform.

False Positive Indicators

Legitimate activity that looks suspicious out of context, and the checks that confirm it's benign.

FALSE POSITIVE

Legitimate Vendor Or Account Change

Reported through the proper channel, not discovered blind
A vendor's account manager change or updated banking detail, reported by the requester through a known process and confirmed against existing account records rather than taken at face value from the email alone.
FALSE POSITIVE

Internal Phishing Simulation

A security awareness test, not a live attempt
Check with the security awareness team before escalating anything that looks like a textbook phishing template. Simulation platforms leave recognizable markers once you know where to look.
FALSE POSITIVE

Unusually Worded Internal Email

Odd phrasing from a real colleague, misread as an attack
A user flags a legitimate internal message because the tone or wording felt off. Confirm sender identity and header integrity, then close it out; not every awkward sentence is a lure.

Escalation Criteria

The thresholds that move a case out of the SOC queue and into a room with finance, legal, and leadership.

ESCALATE

Financial Action Already Taken

A wire was sent, or gift cards were purchased
Escalate immediately to finance, legal, and IR. The window to recall a wire transfer is measured in hours, not days, and it closes fast once funds clear the receiving bank.
ESCALATE

Evidence Of Account Compromise

An attacker-created forwarding rule, or an unfamiliar sign-in
Treat this as an active account compromise, not a phishing report. The response scope is different: credential reset, session revocation, and a mailbox audit, not just a message takedown.
ESCALATE

Multiple Users Targeted With The Same Lure

A pattern, not a coincidence
Treat it as a campaign and escalate as an incident rather than working through a series of individual reports one at a time. The blast radius and the response plan both change at that point.

Containment Actions

Once a case is confirmed, these are the actions that stop it from continuing or repeating.

CONTAIN

Reset Credentials And Revoke Sessions

Immediately, for any compromised account
Reset the password and revoke every active session and token, not just the ones currently visible. A stale token left alive is how an attacker keeps access after a password reset that looked clean.
CONTAIN

Remove Malicious Mailbox Rules

Forwarding, hiding, or auto-delete rules the attacker created
Audit the full rule set on the mailbox, not just the rule that triggered the alert. Attackers sometimes leave a second, quieter rule as a fallback.
CONTAIN

Block IOCs And Purge The Message

At the gateway first, then across every mailbox it reached
Block the sender domain and any other indicators at the mail gateway, then search and purge the message org-wide. Blocking without purging leaves copies sitting in inboxes that already received it.
CONTAIN

Contact The Receiving Bank

Immediately, if a wire transfer occurred
Attempt a recall through the receiving bank as fast as possible. This is a time-critical step that should happen in parallel with the rest of containment, not after it.
CONTAIN

Notify Affected Users And Leadership

Directly, not informally
Notify everyone the message reached. If executive impersonation was involved, brief leadership directly rather than letting it surface through a hallway conversation or a customer call.