SOC Analyst
Safe Phishing Alert Triage
Practice defensive phishing triage using a benign scenario and evidence-based documentation.
Practice environment: This is an educational scenario. Work only on systems you own or are authorized to use. Follow employer, equipment and safety procedures in real environments.
STEP 1
Read the alert
Identify reporter, message time, sender context and what triggered concern.
STEP 2
Inspect safely
Use provided benign indicators; do not open unknown attachments or visit suspicious links.
STEP 3
Assess indicators
Review domain/URL context, urgency, requested action and authentication information when available.
STEP 4
Determine scope
Check whether the simulated message targets one or multiple users.
STEP 5
State confidence
Separate confirmed facts, suspicious indicators and unknowns.
STEP 6
Write the disposition
Document severity reasoning and the escalation or closure recommendation.
Finish the lab
Write a short ticket-style summary: symptom, scope, evidence, hypothesis, action or recommendation, and verification.