BEC & Phishing Response.
Verify Before You Wire, Every Time.
A static process reference: the sources a BEC or phishing case typically comes in through, the triage steps that separate a targeted user from a compromised mailbox, the true and false positive indicators that keep the queue honest, and the escalation and containment actions once a case is confirmed real. Not a substitute for an org's own IR plan or legal counsel, just the reference. For working an active case, see PHISHOPS; for header/SPF/DKIM/DMARC analysis, see MAILSCOPE.
Alert & Report Overview
A BEC or phishing case rarely starts from one clean signal. It shows up through several different channels, and each one implies a slightly different starting point for the investigation.
Common Trigger Sources [T1566 Phishing]
User-reported suspicious email ├── An employee forwards or flags a message through the phish-report button or a support ticket // still the most common entry point, and often the fastest signal available Mail gateway / SEG detection ├── The secure email gateway flags a message on spoofing, malicious link, or malicious attachment signatures // automated detection buys time, it doesn't replace a header review Unusual mailbox rule creation alert ├── A rule engine or M365/Google Workspace alert fires on a newly created forwarding or hide-from-inbox rule A strong early signal of account compromise, not just a phishing attempt Wire transfer request flagged by finance ├── A finance approval workflow flags an unusual or out-of-cycle payment request // often the first sign anyone catches on a BEC that's already partway through New mail-forwarding rule added to a mailbox ├── Surfaced through mailbox audit logging rather than a user report // this one is frequently found only in retrospect, after the fact Executive impersonation report ("CEO fraud") ├── A user reports a request that appears to come from a senior leader, usually urgent and out of the ordinary // authority plus urgency, the pattern that defines the whole category
Initial Triage Steps
The order matters. Evidence handling comes before analysis, and account-compromise checks come before you decide this is "just" a phishing report.
Triage Steps, In Order
1. Preserve the original message with full headers ├── Get the raw .eml/.msg file or the complete header text directly from the mailbox └── Don't let the user forward it — forwarding strips or rewrites the headers you need // this is the evidence the rest of the case depends on 2. Check sender authentication results ├── Review SPF, DKIM, and DMARC pass/fail on the original message └── Check the sending domain for lookalikes: character substitution, an added hyphen, a similar-looking TLD // authentication failures alone don't prove malice, but they narrow the field fast 3. Rule out account compromise, not just targeting ├── Check for new mailbox forwarding rules, new inbox rules, and recent sign-ins └── Flag any sign-in from an unfamiliar location or ASN // a targeted user and a compromised mailbox need very different responses 4. Identify exactly what was requested ├── A wire transfer, gift cards, a credential-harvesting link, or a malicious attachment // the ask drives urgency more than the lure itself does 5. Check the blast radius ├── Search for the same or a similar message across other mailboxes // one report is rarely the full picture
True Positive Indicators
Signals that point to a real attempt in progress, not a false alarm or an internal test.
Authentication Failure Or Lookalike Domain
Urgency Plus Authority Plus A Financial Ask
Reply-To Differs From The Visible From Address
An Unexplained New Mailbox Rule
Impossible Travel Or An Unfamiliar ASN
False Positive Indicators
Legitimate activity that looks suspicious out of context, and the checks that confirm it's benign.
Legitimate Vendor Or Account Change
Internal Phishing Simulation
Unusually Worded Internal Email
Escalation Criteria
The thresholds that move a case out of the SOC queue and into a room with finance, legal, and leadership.
Financial Action Already Taken
Evidence Of Account Compromise
Multiple Users Targeted With The Same Lure
Containment Actions
Once a case is confirmed, these are the actions that stop it from continuing or repeating.