How we use VMRay to support Expel for Phishing
ID: 8b25f823-ab2f-5d72-9e8a-df1bfda9d93e
STIX ID: report--8b25f823-ab2f-5d72-9e8a-df1bfda9d93e
Feed Name: Expel Blog
Threat Score
This post describes Expel's managed phishing investigation workflow using VMRay for static and dynamic analysis of suspicious URLs and attachments, demonstrates examples of credential-harvesting pages and macro-enabled Excel payload behavior, and explains how analysts pivot from sandbox indicators to customer EDR, SIEM, and network logs to determine scope and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
