Mandiant, Inc.
Detection of credential spearphishing attacks using email analysis

Last updated:

Abstract:

A non-transitory computer readable storage medium having stored thereon instructions when executable by a processor perform operations including responsive to receiving an email including a URL, conducting an analysis of the email including: (i) analyzing a header and a body, and (ii) analyzing the URL; analyzing contents of a web page directed to by the URL; generating a score indicating a level of confidence the email is associated with a phishing attack based on at least one of the analysis of the email or the analysis of the contents of the web page; and responsive to the score being below a threshold, virtually processing the web page to determine whether the web page is associated with the phishing attack is shown.

Status:
Grant
Type:

Utility

Filling date:

30 Sep 2015

Issue date:

24 Mar 2020