Location Research Breakthrough Possible @S-Logix pro@slogix.in

Detecting Phishing Infrastructure Targeting Rocket.Chat Users Through Threat Intelligence IOC Enrichment and Phishing Campaign Correlation

Description

Enterprise organizations may deploy Rocket.Chat as a self-hosted collaboration and messaging platform for internal communication. Users may receive messages containing URLs, attachments, or other content that could be used as part of a phishing attack.

Attackers commonly create phishing infrastructure that imitates legitimate services or uses malicious URLs to deceive users into visiting attacker-controlled resources. If an organization has no mechanism to correlate known phishing indicators with its internal security telemetry, phishing activity may remain undetected.

Cyber Threat Intelligence helps address this problem by collecting known malicious URLs and domains, enriching them with external intelligence, and correlating the indicators with activity observed in the enterprise environment.

In this use case, an enterprise-like Rocket.Chat server is deployed on Ubuntu inside an isolated laboratory. A controlled phishing scenario is created using Gophish, an open-source phishing simulation platform. The simulation uses only authorized laboratory users and test infrastructure.

OpenCTI is used as the central Cyber Threat Intelligence platform for collecting, organizing, enriching, and correlating phishing-related threat intelligence.

Open-source intelligence sources such as PhishTank and URLhaus are used to obtain and validate phishing-related URL and domain intelligence.

Zeek monitors network activity generated by the controlled environment, while OpenSearch is used to investigate and visualize the resulting security telemetry.

The controlled phishing campaign generates test indicators that are correlated with the collected CTI. The objective is to determine whether phishing-related indicators can be identified, enriched, correlated, and converted into actionable intelligence for protecting Rocket.Chat users.

The complete workflow is: Rocket.Chat → Controlled Phishing Simulation → Phishing IOC Generation → CTI Collection → IOC Enrichment → OpenCTI Management → Network Telemetry → IOC Correlation → Threat Investigation → Risk Assessment → Intelligence Update

Existing Security Problem

Application: Rocket.Chat

Rocket.Chat is the target collaboration application in this use case. It is deployed as a self-hosted enterprise-like messaging platform within the isolated laboratory. Rocket.Chat may be used to exchange internal messages, project information, URLs, documents, collaboration-related information, notifications, and operational communication. Because users interact with links and other content through collaboration platforms, phishing campaigns can use these communication channels to direct users toward malicious infrastructure.

The organization may have access to external phishing intelligence, but that intelligence may not be connected to internal security monitoring. As a result, a phishing URL or domain used during an attack simulation may appear to be an ordinary web request unless the indicator is enriched and correlated with threat intelligence.

Existing Problem:

The security problem is that external phishing intelligence and known malicious URLs or domains may not be correlated with internal user activity and network telemetry. Without CTI correlation, suspicious links accessed through Rocket.Chat may lead to malicious infrastructure and potential credential theft while the phishing activity remains undetected.

The security problem is therefore:

External Phishing Intelligence → Known Malicious URL / Domain → No CTI Correlation → User Receives Suspicious Link → User Accesses URL → Malicious Infrastructure → Potential Credential Theft → Phishing Activity May Remain Undetected

The proposed solution introduces phishing intelligence collection, IOC validation, IOC enrichment, OpenCTI-based threat intelligence management, controlled phishing simulation, network telemetry collection, IOC correlation, phishing infrastructure identification, threat-context analysis, risk-based investigation, and intelligence-driven response.

Attack

Specific Attack: Phishing Infrastructure

The controlled attack scenario demonstrates how phishing infrastructure can be identified through threat intelligence correlation. A simulated phishing campaign is created using Gophish within the isolated laboratory. The simulation does not target real users or external organizations. Test accounts and controlled infrastructure are used exclusively. The objective is to determine whether phishing-related indicators generated during the controlled campaign can be identified and correlated with threat intelligence.

The assessment focuses on URL reputation, domain reputation, IOC source, IOC confidence, phishing classification, URL characteristics, user interaction, destination infrastructure, network activity, time of activity, potential credential-theft risk, and impact on Rocket.Chat users.

Attack Behavior:
Phishing Simulation
Controlled Phishing URL
Test User Interaction
Network Request
Zeek Telemetry
Phishing IOC
OpenCTI Correlation
Threat Context
Phishing Detection
Investigation

Security Concept

Threat Intelligence–Driven Phishing Detection:

The primary security concept is Threat Intelligence–Driven Phishing Detection.

The objective is to combine phishing intelligence with internal security telemetry to identify suspicious URLs and domains associated with phishing activity. The assessment considers URL reputation, domain reputation, IOC source, IOC confidence, phishing classification, URL characteristics, user interaction, destination infrastructure, network activity, time of activity, potential credential-theft risk, and impact on Rocket.Chat users.

The secure processing flow is:

Phishing Intelligence Collection
IOC Validation
IOC Enrichment
OpenCTI Intelligence Management
Controlled Phishing Simulation
Network Monitoring
IOC Correlation
Phishing Detection
Threat Investigation
Risk Assessment
Security Response

Defensive Mechanism

Phishing Intelligence Collection

Phishing-related URLs and domains are collected from open-source intelligence sources.

Purpose

Obtain information about known phishing infrastructure.

IOC Validation

Collected indicators are validated before being used for detection.

Purpose

Reduce false positives and unreliable intelligence.

IOC Enrichment

Indicators are enriched with available reputation and threat context.

Purpose

Improve understanding of the phishing infrastructure.

Centralized CTI Management

Gophish is used to reproduce the phishing attack safely.

Purpose

Validate the CTI detection workflow using authorized test users.

Network Monitoring

Zeek records the network activity generated by the controlled phishing scenario.

Purpose

Provide telemetry for identifying suspicious URL/domain access.

IOC Correlation

Observed network indicators are compared with the CTI repository.

Purpose

Determine whether observed activity matches known phishing intelligence.

Threat Context Analysis

Matched indicators are reviewed with their associated intelligence.

Purpose

Determine the credibility and significance of the phishing activity.

Security Investigation

OpenSearch is used to investigate correlated events.

Purpose

Identify affected systems, users, URLs, domains, and activity timelines.

Intelligence Feedback

Validated observations are incorporated into the CTI repository.

Purpose

Improve future phishing detection and threat intelligence.

Security Tools

Primary Threat Intelligence Platform: OpenCTI

OpenCTI is the core Cyber Threat Intelligence platform.

Purpose
  • Store threat intelligence.
  • Manage phishing indicators.
  • Organize threat relationships.
  • Enrich indicators.
  • Correlate threat information.
  • Maintain threat context.
  • Support intelligence-driven investigations.

Primary Phishing Simulation Tool: Gophish

Gophish is the primary attack-simulation tool.

Purpose
  • Create controlled phishing campaigns.
  • Generate test phishing URLs.
  • Simulate phishing messages.
  • Measure controlled user interaction.
  • Validate phishing detection capabilities.

Phishing Intelligence Source: PhishTank

PhishTank provides community-driven phishing URL intelligence.

Purpose
  • Obtain phishing URL intelligence.
  • Validate suspicious URLs.
  • Support IOC enrichment.
  • Provide phishing-related context.

Malicious URL Intelligence Source: URLhaus

URLhaus provides intelligence related to malicious URLs and malware distribution infrastructure.

Purpose
  • Obtain malicious URL indicators.
  • Enrich URL intelligence.
  • Provide additional threat context.
  • Support IOC validation.

Network Monitoring Tool: Zeek

Zeek monitors network activity generated by the controlled environment.

Purpose
  • Monitor network connections.
  • Record DNS activity.
  • Generate connection telemetry.
  • Identify destination infrastructure.
  • Provide data for IOC correlation.

Security Investigation Platform: OpenSearch

OpenSearch is used for centralized investigation and visualization.

Purpose
  • Search network telemetry.
  • Investigate suspicious URL access.
  • Identify affected systems.
  • Review event timelines.
  • Visualize correlated phishing activity.

Target Application: Rocket.Chat

Rocket.Chat is the collaboration application used in the scenario.

Purpose
  • Provide the enterprise-like messaging environment.
  • Provide the communication channel for the controlled phishing scenario.
  • Represent the protected application and its users.

Target Platform: Ubuntu Linux

Ubuntu hosts the Rocket.Chat environment.

Purpose
  • Host Rocket.Chat.
  • Provide the controlled application environment.
  • Generate legitimate network activity.
  • Support the CTI detection scenario.

Security Testing Platform: Kali Linux

Kali Linux provides the controlled security-testing environment.

Purpose
  • Host or interact with the controlled phishing simulation.
  • Validate the CTI detection workflow.
  • Generate authorized test activity.
  • Perform post-detection validation.

Virtualization Platform: VirtualBox

VirtualBox provides the isolated cybersecurity laboratory.

Purpose
  • Host Rocket.Chat/Ubuntu.
  • Host Kali Linux.
  • Isolate phishing simulation traffic.
  • Prevent interaction with real phishing infrastructure.

Process

STEP 01

Prepare the Isolated Rocket.Chat Environment

  • Create an isolated cybersecurity laboratory using VirtualBox.
  • Deploy Ubuntu as the Rocket.Chat server.
  • Deploy Kali Linux as the security-testing system.
  • Configure the isolated virtual network.
  • Assign stable laboratory IP addresses.
  • Create authorized test users.
  • Verify communication between laboratory systems.
  • Confirm that the laboratory cannot interact with real phishing infrastructure.
Tools: VirtualBox + Ubuntu + Kali Linux
STEP 02

Deploy the Rocket.Chat Application

  • Install Rocket.Chat on Ubuntu.
  • Start the required Rocket.Chat services.
  • Verify that the web interface is operational.
  • Create controlled test accounts.
  • Create a test channel.
  • Generate normal collaboration activity.
  • Verify legitimate application functionality.
Tools: Rocket.Chat + Ubuntu
STEP 03

Establish the Normal Network Baseline

  • Access Rocket.Chat from an authorized laboratory client.
  • Send controlled test messages.
  • Access legitimate internal resources.
  • Generate normal collaboration traffic.
  • Monitor the resulting network activity.
  • Record normal communication patterns.
  • Preserve the baseline for comparison.
Tools: Rocket.Chat + Zeek
STEP 04

Deploy OpenCTI

  • Deploy OpenCTI within the isolated environment.
  • Configure the CTI platform.
  • Create the required organization and user accounts.
  • Configure the intelligence workspace.
  • Verify that OpenCTI is operational.
  • Prepare the platform for phishing intelligence ingestion.
Tools: OpenCTI
STEP 05

Collect Phishing Intelligence

  • Obtain phishing-related indicators from open-source intelligence sources.
  • Review relevant URLs and domains from PhishTank.
  • Review malicious URL information from URLhaus.
  • Record indicator types.
  • Record intelligence sources.
  • Record available reputation information.
  • Import suitable indicators into the controlled CTI environment.
Tools: PhishTank + URLhaus + OpenCTI
STEP 06

Validate and Enrich Phishing Indicators

  • Review each collected URL and domain.
  • Validate the source of the indicator.
  • Review available reputation information.
  • Identify associated phishing context.
  • Determine indicator confidence.
  • Remove irrelevant indicators.
  • Add contextual information to OpenCTI.
  • Preserve the validated IOC set.
Tools: OpenCTI + PhishTank + URLhaus
STEP 07

Organize Phishing Intelligence in OpenCTI

  • Create the relevant threat-intelligence objects.
  • Add validated phishing indicators.
  • Categorize URLs and domains.
  • Associate indicators with phishing-related threat information.
  • Record intelligence sources.
  • Record confidence information.
  • Establish relationships between indicators and infrastructure.
  • Prepare the intelligence for correlation.
Tools: OpenCTI
STEP 08

Deploy the Controlled Phishing Simulation

  • Deploy Gophish inside the isolated laboratory.
  • Create a controlled phishing campaign.
  • Use only authorized test users.
  • Configure a safe test phishing page.
  • Use a controlled laboratory URL.
  • Configure the campaign for the laboratory environment.
  • Verify that all phishing activity remains inside the isolated network.
Tools: Gophish
STEP 09

Perform the Controlled Phishing Scenario

  • Send the simulated phishing message to the authorized test account.
  • Access the controlled Rocket.Chat environment.
  • Deliver the simulated phishing content through the authorized laboratory workflow.
  • Allow the test user to interact with the controlled phishing URL.
  • Record the interaction.
  • Monitor the resulting network request.
  • Ensure no real credentials are collected.
Tools: Gophish + Rocket.Chat
STEP 10

Capture Phishing Network Telemetry

  • Monitor the controlled phishing interaction using Zeek.
  • Identify the destination IP or domain.
  • Record the DNS activity.
  • Record the connection metadata.
  • Identify the source system.
  • Record the event timestamp.
  • Preserve the generated telemetry.
Tools: Zeek
STEP 11

Correlate Phishing Activity with CTI

  • Collect the relevant Zeek telemetry.
  • Extract the observed URL/domain indicator.
  • Compare the indicator against OpenCTI intelligence.
  • Identify matching phishing indicators.
  • Retrieve associated threat context.
  • Review the indicator confidence.
  • Generate a potential phishing detection finding.
Tools: Zeek + OpenCTI
STEP 12

Centralize Events in OpenSearch

  • Forward relevant Zeek telemetry to OpenSearch.
  • Organize the network data for investigation.
  • Create searches for phishing-related indicators.
  • Identify suspicious URL/domain access.
  • Identify the affected laboratory system.
  • Review the activity timeline.
Tools: OpenSearch + Zeek
STEP 13

Investigate the Potential Phishing Event

  • Review the matched phishing IOC.
  • Review its intelligence source.
  • Review reputation information.
  • Identify the affected test user/system.
  • Review the accessed URL/domain.
  • Review connection timestamps.
  • Review related DNS activity.
  • Determine whether the event matches the controlled phishing scenario.
Tools: OpenSearch + OpenCTI + Zeek
STEP 14

Validate the CTI Finding

  • Compare the observed URL/domain with the OpenCTI indicator.
  • Confirm that the indicator values match.
  • Confirm the indicator type.
  • Review the intelligence confidence.
  • Verify the corresponding network event.
  • Confirm that the event originated from the controlled phishing simulation.
  • Preserve the validation evidence.
Tools: OpenCTI + Zeek + OpenSearch
STEP 15

Assess Threat Context and Risk

  • Review the intelligence associated with the phishing indicator.
  • Determine the nature of the phishing infrastructure.
  • Evaluate the affected Rocket.Chat user.
  • Consider the potential credential-theft risk.
  • Evaluate the confidence of the intelligence.
  • Review the phishing URL characteristics.
  • Determine the investigation priority.
  • Record the risk context.
Tools: OpenCTI + OpenSearch
STEP 16

Update the Threat Intelligence Repository

  • Record the validated observation in OpenCTI.
  • Associate the observed indicator with the relevant phishing intelligence.
  • Add appropriate internal context.
  • Update confidence information where justified.
  • Record the affected Rocket.Chat environment.
  • Preserve the relationship between the indicator and the observed activity.
Tools: OpenCTI
STEP 17

Validate the Detection Workflow

  • Repeat the controlled phishing scenario inside the isolated laboratory.
  • Verify that Gophish generates the expected test activity.
  • Confirm that Zeek records the network communication.
  • Confirm that the destination matches the CTI indicator.
  • Verify that OpenCTI provides the associated threat context.
  • Verify that OpenSearch displays the correlated event.
  • Compare the repeated result with the initial detection.
Tools: Gophish + Zeek + OpenCTI + OpenSearch
STEP 18

Perform Final CTI Assessment and Strategic Review

  • Review the complete Rocket.Chat phishing-intelligence workflow.
  • Review collected phishing intelligence.
  • Review IOC enrichment.
  • Review OpenCTI relationships.
  • Review Gophish simulation results.
  • Review Zeek telemetry.
  • Review OpenSearch investigation results.
  • Identify intelligence gaps.
  • Recommend periodic phishing IOC updates.
  • Recommend continuous validation of threat indicators.
  • Recommend integration of validated CTI into security monitoring.
  • Finalize the Cyber Threat Intelligence assessment.
Tools: OpenCTI + Gophish + Zeek + OpenSearch

Outcome

  1. A self-hosted Rocket.Chat application is successfully deployed in an isolated enterprise-like environment and used as the protected collaboration application.
  2. Phishing-related URLs and domains are collected from open-source intelligence sources and centralized within OpenCTI.
  3. Phishing indicators are validated and enriched with available reputation and contextual information, improving their reliability for detection.
  4. OpenCTI provides structured management and relationship-based correlation of phishing intelligence, creating reusable CTI for future investigations.
  5. A controlled phishing campaign is safely simulated using Gophish, specifically matching the phishing attack being assessed.
  6. The simulated phishing interaction generates controlled network telemetry, which is captured and analyzed using Zeek without connecting to real phishing infrastructure.
  7. Observed phishing indicators are correlated with threat intelligence, enabling the controlled phishing activity to be identified as a potential malicious event.
  8. OpenSearch provides centralized investigation and visualization of the correlated phishing activity, allowing analysts to review the affected system, destination, timeline, and threat context.
  9. Validated internal observations are incorporated into OpenCTI, improving the organization's reusable phishing intelligence and supporting future detection activities.
  10. The complete Rocket.Chat-focused phishing intelligence collection, IOC validation, enrichment, OpenCTI management, controlled phishing simulation, network monitoring, IOC correlation, threat detection, investigation, risk assessment, intelligence updating, and strategic CTI workflow is successfully demonstrated.
← Previous Project
Project 5 of 5