Its All About Defang

  Challenge Progession:
Act I
Difficulty:
  Location:
Ed's Office
Ed's Office
What is Defang?

This challenge grants us access to the Dosis Neighborhood SOC. Its our job to "Defang" a suspicious email regarding refridgeration renovation. That is to take the risky parts of the email, called IOC or Indicators of Compromise and render them inert. The SOC Phishing Threat Analysis Station gives us an example of how to do this:

  • Replace dots/periods with [.]
  • Replace @ in email addresses with [@]
  • Replace http with hxxp in URLs
  • Replace :// with [://] in URLs
The "defanged" parts of the email will now pose less of a threat to the email recipient. The email will still be readable but URL's, domains, IP addresses, and email adresses will not be in a state where a user could simply click on them.

The Email

The email in question is below. This is the email we must Defang.

Dust Off Your Regex

This first step is to write some regular expression rules to extract the 4 categories of IOC: Domains, IP Addresses, URLs, and Email Addresses. There are some traps here due to some tricky phone numbers and URLs that could masquerade as some other IOC's. Regular expressions are always something I need to refresh myself on before I can get into it. A very helpful tool is to ask your favorite LLM for help writing these rules. These are the ones I landed on:

IOC Regex
Domains (?<=(\s|@))((?!dosisneighborhood|523)(\w+\.))+[a-zA-Z]{2,}
IP Addresses \d{3}\.\d{1,3}\.\d{1,3}\.\d{1,3}
URLs (http|https):\/\/[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}(\/\S*)?
Email Addresses ([a-zA-Z0-9\-]+@(?!dosisneighborhood\.corp)((\w+)\.\w{1,4}))

Enter these values into the corresponding Regex sections and click Apply.

Find URL IOCs
Defang with SED

Remembering the Defang rules, we can use SED commands to make the changes. These commands are like find/replace rules. For example s/\./[.]/g to replace dots with [.] You can also chain several of these commands together using a semicolon.

Refer to the "What is Defang?" section above for the characters to find and replace: ".", "@", "http(s)", and "://".

To apply all of the Defang rules, I used the following SED command:
s/\./[.]/g; s/@/[@]/g; s/http/hxxp/g; s/:\//[://]/g

Enter this value into the Custom SED Commands section and click Apply.

Defang with SED
Submit the Report

Once all 9 IOCs have been identified and defanged, submit the report by clicking the "Send to Security Team" button at the bottom. You will see a warning message if something is incorrect. If you see the report summary then this objective is complete. It should be marked complete in your badge.

Phishing IOC Report