incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
CybersecurityeasyPhishingHigh asset
Scenario

Employee reported a suspicious 'CEO' email and entered credentials

A easy Cybersecurity scenario on Phishing.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.

catalog id · phishing-credential-harvest

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Phishing triage discipline
  • Credential-exposure containment under time pressure
MITRE ATT&CKmitre-attack
  • Phishing · Initial AccessT1566 · TA0001
    MappedHigh confidence

    Trains triage of a credential-harvest phishing email report.

MITRE D3FENDmitre-d3fend
  • Multi-factor AuthenticationD3-MFA
    MappedHigh confidence

    Trains MFA-backed containment when a password may have been disclosed.

  • User Account PermissionsD3-UAP
    MappedMedium confidence

    Trains permission scoping for the user whose credentials may be exposed.

NIST CSF 2.0nist-csf-2
  • Continuous Monitoring · DetectDE.CM · DE
    MappedHigh confidence

    Trains detection from mail-flow and authentication telemetry.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains initial triage and scoping of a reported phishing event.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains session revocation and password-reset workflow.

CISA Cybersecurity Performance Goalscisa-cpg
  • Phishing-Resistant MFA2.E
    MappedHigh confidence

    Trains the MFA baseline that limits credential-theft impact.

  • Email Security2.J
    MappedHigh confidence

    Trains the email-security baseline for resilient phishing handling.

CIS Controls v8cis-controls
  • Email and Web Browser ProtectionsControl 9
    MappedHigh confidence

    Trains the email-protection control the scenario exercises.

  • Security Awareness and Skills TrainingControl 14
    MappedMedium confidence

    Trains the awareness baseline that complements technical controls.