Phishing Intelligence Engine – An Active Defense PowerShell Framework for Phishing Defense with Office 365
The Phishing Intelligence Engine (PIE) is a framework that will assist with the detection and response to phishing attacks. An Active Defense framework built around Office 365, that continuously evaluates Message Trace logs for malicious contents, and dynamically responds as threats are identified or emails are reported.
Features:
- Analyze subjects, senders, and recipients using RegEx and Threat Feed correlation, to determine email risk.
- Automatically respond to attacks by quarantining mail, blocking senders, and checking for clicks.
- Sandbox analytics on all flagged email attachments and links.
- Dynamic Case Management integration and metrics tracking.
- Prevent sensitive data loss and verify corporate email security.
Install & Usage
There are multiple aspects of this framework that all work together to detect and respond to Phishing attacks:
PIE Message Trace Logging
1)The core of the Phishing Intelligence Engine – provides ongoing logging via the API, third-party tool integrations, and automated email response.
Office 365 Ninja
2)The response arm of PIE. Quarantine mail, block senders, change credentials, check Office 365 configurations, and more.
3) SPAM Tracker
List updater for ongoing tracking of spammer email addresses.
LogRhythm SIEM Dashboards
4)Analyst and Investigation Dashboards, which allow for searching and aggregation of Office 365 Data within the LogRhythm SIEM.
Alarms and Threat Lists
5)LogRhythm AIE alarm configurations and Threat List integrations.
LogRhythm SmartResponse
6)Plugins that can be integrated with the LogRhythm SIEM, allowing for the automated response to alarms.
Report Phishing Message Button
7)Addon for Microsoft Outlook to allow for easy reporting of Phishing Attacks.
Architecture
8)The high-level overview of the PIE architecture and workflow:
[Additional Information]
Blog Post: https://logrhythm.com/blog/phishing-intelligence-engine-open-source-release/
BSides Vancouver 2018 Slides and Video: https://www.slideshare.net/heinzarelli/pie-bsides-vancouver-2018
BlueHat v17 Slides: https://www.slideshare.net/heinzarelli/phishing-intelligence-engine-bluehat-v17
Black Hat 2017 Slides: https://www.slideshare.net/heinzarelli/security-automation-and-orchestration
Security Weekly Webcast: https://www.youtube.com/watch?v=2oGMoGr4qBI
Copyright 2018 LogRhythm Inc