Exercise - Investigate a threat and reduce human risk with attack simulation training

Completed

A suspicious message referencing a Woodgrove wire-transfer request surfaces as an alert. You need to confirm it was handled correctly, then reduce the finance team's susceptibility to the next attempt.

Important

Prerequisites for this exercise:

  • Access to a Microsoft 365 E5 (or standalone Defender for Office 365 Plan 2) tenant with Microsoft Defender portal permissions sufficient to manage alerts, Threat Explorer, and Attack simulation training.
  • A simulated phishing message available to investigate—use a lab-provided sample if available, or launch your own simulation in Task 1 first and then investigate it in Task 2.

If your tenant restricts live phishing simulations, complete Task 1 up to the simulation-launch step and read through the rest to see the investigation and training flow.

Task 1: Launch a phishing simulation targeting the finance team

  1. Sign in to the Microsoft Defender portal at security.microsoft.com, then go to Email & collaboration > Attack simulation training.
  2. Select Launch a simulation, choose the Credential Harvest technique, and name it Finance – Woodgrove wire-transfer spoof.
  3. Craft the payload to reference a Woodgrove wire-transfer request (or select a similar pre-built payload if available).
  4. Target the finance team group, review, and launch the simulation.

Task 2: Investigate the resulting alert with Threat Explorer

  1. Wait for the simulation to generate delivery data, then go to Email & collaboration > Explorer (Threat Explorer).
  2. Filter by the simulation campaign name or the finance team recipients, and open the message.
  3. Review the Email entity page for that message, including its delivery location and any post-delivery actions (for example, if a user clicked the link before it was blocked).
  4. Go to Incidents & alerts > Alerts, find the alert this simulation generated, and open it.
  5. Walk the alert through its status workflow: set it to In progress while you document your findings, then to Resolved once you've confirmed the simulation was handled as expected and no real compromise occurred.

Task 3: Assign a Training campaign with the correct threshold

  1. Still in Attack simulation training, select Training campaigns > Create a campaign.
  2. Name it Finance – phishing awareness follow-up and assign the training content relevant to wire-transfer and credential-harvest attempts.
  3. Under the training threshold or exclusion settings, confirm you're not excluding users who completed training recently unless that's genuinely intended—set the threshold so everyone who needs the refresher, including anyone who fell for this simulation, is actually included in scope.
  4. Assign the campaign to the finance team group and review the due date and reminder settings before saving.
  5. Reflect: investigating the alert confirmed the technical detection worked. The training campaign is the human-risk half of the response—closing the loop so the same wire-transfer pretext doesn't work as well next time.

You've now investigated a simulated Woodgrove-spoofing threat end to end—Threat Explorer, the Email entity page, and the alert workflow—and assigned a Training campaign scoped to actually reach the finance team, reducing their susceptibility to the next attempt.