Skip to content

MercyChrisSec/threat-analysis-phishing-scenario

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Threat Analysis – Phishing Attack Scenario

Project Overview

This project presents a simulated threat analysis of a phishing attack targeting a small healthcare organization.
The objective is to identify attack methods, evaluate potential impact, and recommend mitigation strategies.


Objective

To analyze a phishing attack scenario, assess the risks, and propose actionable controls to prevent similar incidents.


Methodology

  1. Simulate a phishing email targeting staff
  2. Analyze potential vulnerabilities exploited
  3. Evaluate impact and likelihood
  4. Recommend preventive controls and awareness measures

📊 Threat Analysis Summary

Attack Vector Target Exploited Vulnerability Likelihood Impact Risk Level
Phishing Email Staff Email System Lack of awareness training High Medium High
Credential Harvesting Staff Email Weak password policies Medium High High
Malware Attachment Staff Devices No endpoint protection Medium Medium Medium

Key Findings

  • Staff are susceptible to phishing due to low security awareness
  • Weak passwords increase risk of account compromise
  • Lack of endpoint protection allows malware spread

Recommendations

  • Conduct regular phishing awareness training
  • Implement multi-factor authentication (MFA)
  • Deploy endpoint protection and email filters
  • Regularly review user access rights

Framework Reference

  • NIST Cybersecurity Framework (CSF)
  • CIS Critical Security Controls

Author

Mercy Christopher
Cybersecurity Analyst | GRC & Threat Analysis
LinkedIn: www.linkedin.com/in/mercy-christopher-24bb17350
Email: mercychrispearly@outlook.com

About

Simulated threat analysis of a phishing attack in a small healthcare environment.

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors