INTERFACE: eth0 (PROMISC)SNIFFING
dashboardmodule-01
HIGH

Phishing & Dropper

Interactive simulation and visual analysis of the attack vector.

01Attack Vector Flow

A weaponized email attachment (.docm) uses malicious macros to spawn an abnormal process chain, secretly launching PowerShell hidden from the victim.

Outlook Web
URGENT: Outstanding Invoice #89432
From: billing@trusted-vendor.com
Dear Customer,

Please find attached your outstanding invoice for the previous billing cycle. Failure to process this payment within 24 hours will result in service suspension.
Invoice_89432.docm
142 KB
EDR Process Monitor

02Stager & C2 Drop

The lightweight PowerShell 'stager' reaches out to an external C2 server, downloads the much larger second-stage payload, and drops it into a hidden Temp directory.

powershell.exe
198.51.100.45:443
Local Disk (C:) %TEMP%
Directory empty...

03Analyst Telemetry

SOC Analysts use Endpoint Detection and Response (EDR) tools to trace the attack timeline, correlating the initial Word document to the dropped payload and outbound IP connections.

SOC Telemetry & Event Viewer
TIMESTAMP
SOURCE PROCESS
EVENT TYPE
TARGET / ARTIFACT
Click 'Analyze Endpoint Logs' to reconstruct the attack timeline.