Detection 101: Top Detections for Email Phishing and BEC
ID: cb6e2c7a-d4ed-50da-a44c-9d9844eaa450
STIX ID: report--cb6e2c7a-d4ed-50da-a44c-9d9844eaa450
Feed Name: ReliaQuest Blog
This blog post outlines detection and response best practices for email phishing and business email compromise (BEC), recommending a multi-layered approach that leverages email security, EDR, CASB, MFA, user behavior analytics, network IDS, and threat intelligence. It provides baseline detection rules for single and multiple data sources, describes multi-point detections (e.g., phishing link clicked followed by MFA), advocates automated playbook responses for high-fidelity alerts, and recommends measuring detection effectiveness (MITRE ATT&CK coverage, false-positive rates, MTTR).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
