SOC Analysis | SIEM | Phishing Investigation

Phishing Alert Investigation Using Splunk

A simulated SOC investigation using Splunk to triage a medium-severity phishing alert, correlate email and firewall telemetry, evaluate business context, and document a defensible false positive disposition.

Splunk Phishing Alert Triage Incident Classification

Investigation Snapshot

Alert context and objective

Alert ID

8814

Severity

Medium

Alert Type

Inbound Email Containing Suspicious External Link

Primary Artifact

hrconnex.thm

Data Reviewed

Email + Firewall Telemetry

Tool

Splunk Enterprise

Disposition

False Positive

Objective: Determine whether the suspicious onboarding email represented legitimate business activity or a phishing attempt.

Alert Details

Activity Time: August 14, 2026 at 20:06:10

Direction: Inbound

Sender: onboarding@hrconnex.thm

Recipient: j.garcia@thetrydaily.thm

Domain: hrconnex.thm

URL: https://hrconnex.thm/onboarding/15400654060/j.garcia

Investigation

From alert triage to telemetry correlation

  1. 01Reviewed the phishing alert and identified the external domain and embedded onboarding URL as the primary investigation artifacts.
  2. 02Searched Splunk for hrconnex.thm to identify related events across the available telemetry.
  3. 03Reviewed related email events showing internal correspondence that established the recipient was expecting an onboarding message from the identified third-party HR provider.
  4. 04Expanded the investigation to firewall telemetry using:datasource=firewall
  5. 05Narrowed the firewall investigation using:datasource=firewall hrconnex.thm
  6. 06Interpreted the absence of matching firewall events as a lack of corroborating firewall evidence within the selected six-hour investigation window.

Findings & Disposition

Key evidence and closure rationale

Key Evidence

  • The recipient was expecting an onboarding email.
  • Internal correspondence identified hrconnex.thm as a third-party HR provider.
  • The sender and domain were consistent with the expected onboarding activity.
  • No matching firewall events were identified for the linked domain during the investigation window.
  • No additional malicious indicators were identified in the email and firewall telemetry reviewed during the investigation.

Disposition

False Positive

Closure Rationale

The email appeared consistent with an expected onboarding message from a known third-party HR provider. Internal correspondence confirmed the recipient was expecting the email, and no matching firewall activity for the linked domain was identified during the investigation window.

Key Takeaway

Alert severity alone was insufficient to determine risk. Correlating the email with business context and firewall telemetry changed the disposition from suspicious activity to a defensible false positive.

Investigation Evidence

Investigation screenshots

Expandable screenshots are shown in investigation order.

Initial Phishing Alert

Shows the medium-severity alert for an inbound email containing a suspicious external link.

SOC simulator alert queue showing phishing alert ID 8814
Alert Evidence Review

Shows the sender, recipient, external domain, onboarding URL, and email artifacts identified during initial triage.

Phishing alert details with sender recipient subject and URL artifacts
Splunk Domain Correlation

Shows the Splunk search for hrconnex.thm and related email telemetry used to establish business context.

Splunk search results for hrconnex.thm showing related email telemetry
Firewall Telemetry Investigation

Shows the query datasource=firewall hrconnex.thm with no matching firewall events identified in the selected window.

Splunk firewall search for hrconnex.thm showing no matching results
Incident Classification and Closure

Shows the completed incident report, related entities, closure rationale, and false positive classification.

Incident report showing false positive classification and closure rationale

Skills Demonstrated

Security analysis skills practiced

Splunk Alert Triage Phishing Analysis Log Analysis Event Correlation Incident Classification Incident Documentation