← Back to Attack / Defense Lab
OSI LAYER 7 // Application Layer

Phishing

Phishing is a social-engineering attack that uses deceptive messages or pages to make a person reveal information, execute an action, or deliver an attacker-controlled payload.

PREMIUM RESOURCE
01 // HOW IT WORKS

Mechanism

A message creates urgency or trust, directs the recipient to a deceptive destination, and attempts to capture credentials, induce a payment, or cause execution. The key defensive question is whether the identity, destination, and requested action can be independently verified.

02 // DETECTION

Indicators to watch

Watch for unusual sender domains, look-alike addresses, unexpected login pages, shortened or mismatched URLs, new inbox rules, impossible-travel sign-ins, suspicious OAuth consent, and reports from users.

03 // ATTACK FLOW

Concept diagram

01User inbox↓
02Deceptive message↓
03Fake destination / request↓
04Credential or action risk↓
05Email + identity controls
04 // PREVENTION

Defensive controls

Use phishing-resistant MFA where possible, secure email gateways, SPF/DKIM/DMARC, URL and attachment analysis, user reporting, domain protection, browser isolation, and rapid credential/session revocation.

05 // SECURITY TOOL

Recommended security control

Email gateway / Microsoft Defender for Office 365

Use an authorized mail-security lab to inspect headers, links, and authentication results. Never send deceptive messages to real users without permission.

06 // DEFENSE TOOL

Defense tool

The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.

PREMIUMBuild Soon
◈
DEFENSE TOOL // BUILD SOONThe administrator can attach a file or external tool link from the private admin portal.
AUTHORIZED LEARNING

All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.