AI-era phishing and the initial foothold
The attacker gets in. This session covers the 2024–2025 phishing techniques most SOC training does not touch — machine-written lures and deepfaked verification — and follows the intrusion from the click to the first beacon.
- When
- Sat 24 Oct 2026 · 10:30–13:30 IST
- Where
- Bangalore or virtual
- Cohort size
- 25 in person · 40 including virtual
Sessions can be booked individually, or take the full six-session cohort.
What you leave able to do
- Distinguish AI-written phishing from human-written on header evidence
- Work a deepfake-assisted business email compromise
- Trace a C2 beacon back to its initial foothold
Run of play
- 1
The lure
What changes when the phishing email was not written by a person.
- 2
The foothold
Four clicks, a beacon, and 23 queued alerts.
The case
Where this sits in the story
All six Saturdays run on one continuous breach, so every session picks up where the last one left off.
The correlation held: one actor, many logs. Then Priya finds a finance host quietly beaconing out, and the campaign moves from reconnaissance to a live foothold. By the end of the session Silent Phantom has opened a second front — a payroll phish that four people have already clicked.
Who this session suits
Analysts comfortable at a Linux prompt who need the detection side: network evidence, Windows telemetry and the phishing chain.
Scope
What this session covers
- TCP/IP attack patterns, suspicious ports and firewall log attribution
- C2 beaconing in NetFlow, and DNS tunnelling by query-length anomaly
- Windows Security and Sysmon events, and reading a process tree
- Detecting credential dumping via Sysmon Event ID 10
- MTTD and MTTR calculated from real epoch timestamps
- Email header forensics: SPF, DKIM and DMARC failures as spoofing evidence
- Decoding Base64 payloads and producing blockable IOCs
- Suricata alert triage, and writing your first suppress rule
- Web shell and SQL injection detection from nginx access logs
Hands-on
The labs you work
6 hands-on labs, 345 minutes of lab time. Each runs in a cloud terminal against real evidence — logs, PCAPs, event data — and is graded on what you find, not on a multiple-choice answer. Lab access continues for 3 months, so the work does not stop when the session ends.
- 1Networking Essentials for SOC Analystssoc-foundations55 min
- 2Windows & Sysmonsoc-foundations60 min
- 3Alert Triage and Ticketingsoc-foundations60 min
- 4Phishing Email Analysissoc-foundations65 min
- 5Suricata IDS Alert Triagesoc-foundations50 min
- 6Web Attack Detectionsoc-foundations55 min
Tools used
- Sysmon
- Windows Event Logs
- Suricata
- NetFlow
- nginx logs
- Python3
- jq
MITRE ATT&CK coverage (21)
- T1003.001 OS Credential Dumping: LSASS Memory
- T1021.003 Remote Services: Distributed Component Object Model
- T1027 Obfuscated Files or Information
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1071 Application Layer Protocol
- T1071.004 Application Layer Protocol: DNS
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087 Account Discovery
- T1110 Brute Force
- T1190 Exploit Public-Facing Application
- T1486 Data Encrypted for Impact
- T1550.002 Use Alternate Authentication Material: Pass the Hash
- T1550.003 Use Alternate Authentication Material: Pass the Ticket
- T1562 Impair Defenses
- T1566.001 Phishing: Spearphishing Attachment
- T1566.002 Phishing: Spearphishing Link
- T1572 Protocol Tunneling
Schedule
The full cohort
One continuous case across six Saturdays. Sessions build on each other, and each one can also be booked on its own.
- Sat 17 Oct 2026Foundations and the first alert10:30–13:30 ISTDetails →
- Sat 24 Oct 2026AI-era phishing and the initial foothold10:30–13:30 ISTYou are here
- Sat 31 Oct 2026Endpoint investigation and containment10:30–13:30 ISTDetails →
- Sat 7 Nov 2026Diwali holiday — no sessionNo session
- Sat 14 Nov 2026Cloud SOC and lateral movement10:30–13:30 ISTDetails →
- Sat 21 Nov 2026Detection engineering and automation10:30–13:30 ISTDetails →
- Sat 28 Nov 2026Immersive day and certification exam10:30–17:30 IST · full dayDetails →
Taking the whole cohort?
The six sessions are one continuous case, and the full course page carries the curriculum, the certification detail and the cohort pricing.

