Skip to main content
Tier One

Report writer

Fill in the blanks on the left. The worked example on the right shows the standard a Tier 2 reviewer expects.

Two or three sentences: what happened, to whom, and what you concluded.

Worked example

At 13:04Z j.rivera (Finance) reported a phishing email from a look-alike domain. Proxy logs confirm credentials were submitted to a domain registered two days earlier. Assessed as a confirmed credential-phishing compromise; escalated to Tier 2.

One line per event, in UTC, oldest first.

Worked example

12:58Z Spoofed mail delivered (SPF/DKIM/DMARC fail)
13:01Z User clicked rewritten URL
13:02Z HTTP POST of credentials (412 bytes)
13:04Z User self-reported via Report Phishing

Hosts, accounts and services involved.

Worked example

WKS-FINANCE-14 (high criticality), account j.rivera

IPs, domains, hashes, filenames.

Worked example

Sender: payments@northwlnd-mfg.example
Landing domain: portal-northwind-invoices.example (created 2026-07-22)
IP: 185.234.72.19

What you actually did, in order.

Worked example

Confirmed header authentication failures; ran WHOIS and IP reputation; verified POST in proxy logs; requested session revocation and password reset; blocked both domains; searched mail store for other recipients.

What should happen next, and who owns it.

Worked example

Tier 2 to hunt for logins to j.rivera from unfamiliar IPs. Add both domains to the block list permanently. Consider phishing-resistant MFA for Finance.

Preview

# Incident report — A-1041 Credential phishing email reported by user — link clicked

## Summary

_Not completed_

## Timeline

_Not completed_

## Affected assets

_Not completed_

## Indicators of compromise

_Not completed_

## Actions taken

_Not completed_

## Recommendation

_Not completed_