• Skip to primary navigation
  • Skip to content
  • Skip to footer
Security Content Security Content
  • Detections
  • Analytic Stories
  • Playbooks
  • Blog
  • About
    • Type
      • Investigation
      • Response
    • Use Case
      • Endpoint
      • Enrichment
      • Phishing
    • D3fend Technique Category
      • Credential Eviction
      • File Analysis
      • Identifier Analysis
      • Network Isolation
    • Soar App
      • AD LDAP
      • AWS IAM
      • Azure AD Graph
      • Carbon Black Response
      • Cisco Umbrella
      • CrowdStrike OAuth API
      • Cylance
      • Falcon Host API
      • G Suite for GMail
      • Jira
      • LDAP
      • Palo Alto Networks Firewall
      • Panorama
      • Phantom
      • PhishTank
      • Reversing Labs
      • SMTP
      • SSH
      • ServiceNow
      • Splunk
      • Splunk Attack Analyzer Connector for Splunk SOAR
      • Threat Grid
      • TruSTAR
      • VirusTotal
      • VirusTotal v3
      • WildFire
      • Windows Defender ATP
      • Windows Remote Management
      • Zscaler
      • aws_iam
      • azure_ad_graph
      • microsoft_ad_ldap
      • urlscan.io

    Phishing

    Name SOAR App D3FEND Use Case
    AD LDAP Account Locking AD LDAP Account Locking Phishing, Endpoint
    AWS IAM Account Locking AWS IAM Account Locking Phishing, Endpoint
    Active Directory Disable Account Dispatch AD LDAP, Azure AD Graph Account Locking Phishing, Endpoint
    Azure AD Locking Account Azure AD Graph Account Locking Phishing, Endpoint
    Cisco Umbrella DNS Denylisting Cisco Umbrella DNS Denylisting Phishing, Endpoint
    CrowdStrike OAuth API Dynamic Analysis CrowdStrike OAuth API Dynamic Analysis Enrichment, Phishing, Endpoint
    DNS Denylisting Dispatch   DNS Denylisting Phishing, Endpoint
    Dynamic Analysis Dispatch   Dynamic Analysis Enrichment, Phishing, Endpoint
    G Suite for GMail Message Identifier Activity Analysis G Suite for GMail Identifier Activity Analysis Phishing
    Panorama Outbound Traffic Filtering Panorama   Phishing, Endpoint
    PhishTank URL Reputation Analysis PhishTank Identifier Reputation Analysis Enrichment, Phishing
    Splunk Message Identifier Activity Analysis Splunk Identifier Activity Analysis Phishing
    Splunk_Attack_Analyzer_Dynamic_Analysis Splunk Attack Analyzer Connector for Splunk SOAR Dynamic Analysis Enrichment, Phishing, Endpoint
    URL Outbound Traffic Filtering Dispatch     Phishing, Endpoint
    UrlScan IO Dynamic Analysis urlscan.io Dynamic Analysis Enrichment, Phishing, Endpoint
    VirusTotal V3 Dynamic Analysis VirusTotal v3 Dynamic Analysis Enrichment, Phishing, Endpoint
    ZScaler Outbound Traffic Filtering Zscaler   Phishing, Endpoint
    • Twitter
    • GitHub
    • Feed
    © 2023 Splunk Threat Research Team (STRT). Powered by Jekyll & Minimal Mistakes.