Phishing Intelligence Collection
Phishing-related URLs and domains are collected from open-source intelligence sources.
Obtain information about known phishing infrastructure.
Enterprise organizations may deploy Rocket.Chat as a self-hosted collaboration and messaging platform for internal communication. Users may receive messages containing URLs, attachments, or other content that could be used as part of a phishing attack.
Attackers commonly create phishing infrastructure that imitates legitimate services or uses malicious URLs to deceive users into visiting attacker-controlled resources. If an organization has no mechanism to correlate known phishing indicators with its internal security telemetry, phishing activity may remain undetected.
Cyber Threat Intelligence helps address this problem by collecting known malicious URLs and domains, enriching them with external intelligence, and correlating the indicators with activity observed in the enterprise environment.
In this use case, an enterprise-like Rocket.Chat server is deployed on Ubuntu inside an isolated laboratory. A controlled phishing scenario is created using Gophish, an open-source phishing simulation platform. The simulation uses only authorized laboratory users and test infrastructure.
OpenCTI is used as the central Cyber Threat Intelligence platform for collecting, organizing, enriching, and correlating phishing-related threat intelligence.
Open-source intelligence sources such as PhishTank and URLhaus are used to obtain and validate phishing-related URL and domain intelligence.
Zeek monitors network activity generated by the controlled environment, while OpenSearch is used to investigate and visualize the resulting security telemetry.
The controlled phishing campaign generates test indicators that are correlated with the collected CTI. The objective is to determine whether phishing-related indicators can be identified, enriched, correlated, and converted into actionable intelligence for protecting Rocket.Chat users.
The complete workflow is: Rocket.Chat → Controlled Phishing Simulation → Phishing IOC Generation → CTI Collection → IOC Enrichment → OpenCTI Management → Network Telemetry → IOC Correlation → Threat Investigation → Risk Assessment → Intelligence Update
Rocket.Chat is the target collaboration application in this use case. It is deployed as a self-hosted enterprise-like messaging platform within the isolated laboratory. Rocket.Chat may be used to exchange internal messages, project information, URLs, documents, collaboration-related information, notifications, and operational communication. Because users interact with links and other content through collaboration platforms, phishing campaigns can use these communication channels to direct users toward malicious infrastructure.
The organization may have access to external phishing intelligence, but that intelligence may not be connected to internal security monitoring. As a result, a phishing URL or domain used during an attack simulation may appear to be an ordinary web request unless the indicator is enriched and correlated with threat intelligence.
The security problem is that external phishing intelligence and known malicious URLs or domains may not be correlated with internal user activity and network telemetry. Without CTI correlation, suspicious links accessed through Rocket.Chat may lead to malicious infrastructure and potential credential theft while the phishing activity remains undetected.
The security problem is therefore:
The proposed solution introduces phishing intelligence collection, IOC validation, IOC enrichment, OpenCTI-based threat intelligence management, controlled phishing simulation, network telemetry collection, IOC correlation, phishing infrastructure identification, threat-context analysis, risk-based investigation, and intelligence-driven response.
The controlled attack scenario demonstrates how phishing infrastructure can be identified through threat intelligence correlation. A simulated phishing campaign is created using Gophish within the isolated laboratory. The simulation does not target real users or external organizations. Test accounts and controlled infrastructure are used exclusively. The objective is to determine whether phishing-related indicators generated during the controlled campaign can be identified and correlated with threat intelligence.
The assessment focuses on URL reputation, domain reputation, IOC source, IOC confidence, phishing classification, URL characteristics, user interaction, destination infrastructure, network activity, time of activity, potential credential-theft risk, and impact on Rocket.Chat users.
The primary security concept is Threat Intelligence–Driven Phishing Detection.
The objective is to combine phishing intelligence with internal security telemetry to identify suspicious URLs and domains associated with phishing activity. The assessment considers URL reputation, domain reputation, IOC source, IOC confidence, phishing classification, URL characteristics, user interaction, destination infrastructure, network activity, time of activity, potential credential-theft risk, and impact on Rocket.Chat users.
The secure processing flow is:
Phishing-related URLs and domains are collected from open-source intelligence sources.
Obtain information about known phishing infrastructure.
Collected indicators are validated before being used for detection.
Reduce false positives and unreliable intelligence.
Indicators are enriched with available reputation and threat context.
Improve understanding of the phishing infrastructure.
Gophish is used to reproduce the phishing attack safely.
Validate the CTI detection workflow using authorized test users.
Zeek records the network activity generated by the controlled phishing scenario.
Provide telemetry for identifying suspicious URL/domain access.
Observed network indicators are compared with the CTI repository.
Determine whether observed activity matches known phishing intelligence.
Matched indicators are reviewed with their associated intelligence.
Determine the credibility and significance of the phishing activity.
OpenSearch is used to investigate correlated events.
Identify affected systems, users, URLs, domains, and activity timelines.
Validated observations are incorporated into the CTI repository.
Improve future phishing detection and threat intelligence.
OpenCTI is the core Cyber Threat Intelligence platform.
Gophish is the primary attack-simulation tool.
PhishTank provides community-driven phishing URL intelligence.
URLhaus provides intelligence related to malicious URLs and malware distribution infrastructure.
Zeek monitors network activity generated by the controlled environment.
OpenSearch is used for centralized investigation and visualization.
Rocket.Chat is the collaboration application used in the scenario.
Ubuntu hosts the Rocket.Chat environment.
Kali Linux provides the controlled security-testing environment.
VirtualBox provides the isolated cybersecurity laboratory.