Phishing & Social Engineering Defense

Articles about phishing & social engineering defense from security operations practitioners.

Phishing & Social Engineering Defense

Deepfake attacks are starting to show up in SOC telemetry

A second remote-management tool on a newly issued laptop is what a deepfake-enabled hire looks like in your logs. Here are the correlations that catch the infrastructure around the fake, and the one rule nobody can build reliably yet.

MKMarta K. · Sep 25, 2026
Phishing & Social Engineering Defense

Security awareness training: what it actually buys

I've signed awareness-training renewals for a decade and rarely had a credible way to tie them to a prevented incident. Here's what the line item reliably delivers, what it cannot carry on its own, and where incremental phishing budget reduces exposure more directly.

DCDaniel C. · Sep 19, 2026
Phishing & Social Engineering Defense

Secure email gateway: what it catches, and what still lands in triage

I've run triage behind Proofpoint and Defender for Office 365. A secure email gateway removes a large volume of spam, malware, and known-bad content before delivery, but compromised accounts, text-only BEC, thread hijacks, and later-changing URLs can still land clean. Here's the post-delivery workflow that closes that gap.

MKMarta K. · Sep 19, 2026
Phishing & Social Engineering Defense

Recent FBI phishing advisories: what the SOC should pull forward

Here's how I turn that advisory into rules a detection engineer can build and procedure a security leader can enforce, and the cadence that keeps this current without chasing every headline.

MKMarta K. · Sep 19, 2026
Phishing & Social Engineering Defense

Social engineering patterns we've seen get past filters

The alert that taught me the most about social engineering never fired on the message. It fired eleven days later, on an Okta login from an anonymizing proxy against a Super Admin account our own help desk had reset. Every filter I owned had nothing to inspect, because the attack produced no message artifact at all.

MKMarta K. · Jul 25, 2026
Phishing & Social Engineering Defense

AI phishing detection: real lift or marketing lift?

AI phishing detection is real lift on payload-less attacks like BEC, but it becomes marketing lift when it mostly re-scores known-bad your gateway already blocks.

DCDaniel C. · Jul 11, 2026
Phishing & Social Engineering Defense

What vishing looks like from the SOC triage seat

Vishing hides in identity logs, not email or endpoint alerts, so the SOC sees the aftermath first. The real signal is a correlated trail: help-desk reset, risky re-enrollment, then anomalous sign-in.

MKMarta K. · Jul 10, 2026
Phishing & Social Engineering Defense

Smishing in 2026: where the attacks are actually landing

Smishing hasn't stayed in the consumer fraud category it started in. The SMS attacks showing up in enterprise queues in 2026 are multi-stage credential harvesting campaigns: IT helpdesk impersonation, MFA code interception, RCS delivery that bypasses carrier filters. Most SOC tooling wasn't built to catch any of it.

MKMarta K. · Jul 4, 2026
Phishing & Social Engineering Defense

What a phishing investigation actually looks like in 2026

A user-reported phish looked dead on arrival: clean sandbox, benign PDF, expired URL. The real compromise was already live in the identity plane as a replayed session token and an attacker-created OAuth grant, three hours before the runbook caught up.

MKMarta K. · Jun 26, 2026

Stay sharp on security operations

Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.

Phishing & Social Engineering Defense | Future of SecOps