Phishing
Phishing is a social-engineering attack that uses deceptive messages or pages to make a person reveal information, execute an action, or deliver an attacker-controlled payload.
Mechanism
A message creates urgency or trust, directs the recipient to a deceptive destination, and attempts to capture credentials, induce a payment, or cause execution. The key defensive question is whether the identity, destination, and requested action can be independently verified.
Indicators to watch
Watch for unusual sender domains, look-alike addresses, unexpected login pages, shortened or mismatched URLs, new inbox rules, impossible-travel sign-ins, suspicious OAuth consent, and reports from users.
Concept diagram
Defensive controls
Use phishing-resistant MFA where possible, secure email gateways, SPF/DKIM/DMARC, URL and attachment analysis, user reporting, domain protection, browser isolation, and rapid credential/session revocation.
Recommended security control
Email gateway / Microsoft Defender for Office 365
Use an authorized mail-security lab to inspect headers, links, and authentication results. Never send deceptive messages to real users without permission.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.