ChecklistCONSTRUCTEDUntested

First 15 minutes: a user typed their password into a phishing page

Assume the session was taken, not just the password. Revoke first, find everybody else the email reached, and check what the attacker did with the time they had.

high severityInitial AccessT1566.002T1557T1078.004

The clock starts when

A user reports that they entered their password, or approved an MFA prompt, on a page they reached from a link in an email or message.

0 of 9 done
minutes 0 to 5

Assume the session is gone, not only the password

minutes 5 to 10

Stop the next person

minutes 10 to 15

Check what the session did

Do not

  • Do not only reset the password. A stolen session cookie does not need it.
  • Do not open the phishing link from a normal workstation. Use an isolated sandbox, and know that some public scanners publish what you submit.
  • Do not wait for other users to report it before searching for the message.

Escalate now if

  • Sign-ins from an unfamiliar address succeeded after the click.
  • The account is privileged, in finance, or belongs to an executive.
  • More than a handful of users received or clicked it.
  • Inbox rules, forwarding or app consents were created.

Minute sixteen. The checklist ends here and the response does not.

Open the phishing playbook

Why this order

The old version of this incident was a stolen password, and a reset ended it. The current version, built on kits that sit between the user and the real login page, takes the session as well. The attacker is signed in with MFA already satisfied, and the reset alone does not throw them out. Revoking sessions first is what closes that.

The second five minutes are about everybody else. One user reporting a phish is good news, and it is almost never the only user who received it.

What this does not cover

A compromise that has already been used, with rules, consents or new MFA methods in place. If the last window turns any of those up, move to the account compromise material rather than finishing this list.

sources

  1. MITRE ATT&CK T1566.002, Phishing: Spearphishing Link · primary
  2. MITRE ATT&CK T1557, Adversary-in-the-Middle
  3. Microsoft Learn: phishing investigation playbook
  4. NCSC (UK): phishing attacks, defending your organisation

Tags: first-15 · phishing · credentials · aitm · identity · email · T1566.002