incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
CybersecuritymediumBusiness Email Compromise (Vendor Invoice)High asset
Scenario

AP received 'updated wire details' invoice from longstanding vendor — sender domain is one-letter look-alike, $48,250 payment scheduled tomorrow

A medium Cybersecurity scenario on Business Email Compromise (Vendor Invoice).

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.

catalog id · business-email-compromise-vendor-invoice

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Vendor-invoice fraud recognition
  • Out-of-band verification discipline
MITRE ATT&CKmitre-attack
  • Phishing · Initial AccessT1566 · TA0001
    MappedHigh confidence

    Trains BEC-style vendor impersonation recognition.

MITRE D3FENDmitre-d3fend
  • User Behavior AnalysisD3-UBA
    MappedHigh confidence

    Trains behavioral baselines for finance-team request flows.

NIST CSF 2.0nist-csf-2
  • Communications · RespondRS.CO · RS
    MappedHigh confidence

    Trains stakeholder-communication discipline under fraud pressure.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains triage of vendor-invoice anomalies.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains finance-pause and out-of-band-verify workflow.

CISA Cybersecurity Performance Goalscisa-cpg
  • Email Security2.J
    MappedHigh confidence

    Trains the email-security baseline for spoof-resistant flows.

  • Phishing-Resistant MFA2.E
    MappedMedium confidence

    Trains MFA discipline behind mailbox compromise prevention.

CIS Controls v8cis-controls
  • Email and Web Browser ProtectionsControl 9
    MappedHigh confidence

    Trains the email-protection control the scenario exercises.

  • Security Awareness and Skills TrainingControl 14
    MappedHigh confidence

    Trains the awareness baseline for finance-team handling.