An enterprise SOC sees a phishing campaign where messages are grammatically perfect, reference legitimate business projects, and omit typical spelling errors. The team’s keyword and typo-based filters miss most messages. Which detection adjustment best addresses AI-assisted adversary tradecraft?
Select an answer to reveal the explanation.
Short Explanation
Think of AI phishing like a forged check with perfect handwriting: the old tell—typos and bad grammar—no longer helps. You’ve got to watch the bank account: sender behavior, message flow, infrastructure, and whether the request makes sense. That is the trap—polished wording does not mean legitimate wording.
Full Explanation
AI-assisted phishing changes the reliability of low-signal indicators such as spelling errors, awkward phrasing, and obvious template mismatches. The analyst should shift weight toward higher-confidence signals: message delivery timing, authentication results, sender and recipient relationship, URL and attachment reputation, infrastructure reuse, and whether the requested action fits normal business process. Grammar-error and typo-based filters are now weak because generative text can remove the very anomalies those rules were designed to catch. Blocking all inbound email with PDF attachments is overly broad and creates false positives without addressing the underlying campaign behavior. Relying on sender-domain reputation as the primary signal is unreliable because attackers can register lookalike domains, compromise legitimate domains, or use trusted cloud mail services, so reputation alone cannot distinguish AI-composed phishing from normal mail. Exam caveat: AI-assisted tradecraft does not make every email malicious; detection should combine multiple indicators and preserve business workflow. Operational check: tune the mail security platform to alert on anomalous sender-to-recipient patterns, new infrastructure, and out-of-band verification for credential or payment requests.