SANS Challenge Demonstrates Phishing IOC Extraction

Ed Skoudis and the SANS Holiday Hack Challenge present an interactive exercise (dated Dec 25, 2025) that guides participants through triaging a phishing email. The article walks through an email sample, full headers, and an interactive dashboard to extract indicators of compromise—domains, IPv4 addresses, and URLs—using tailored regex patterns and examples.
Scoring Rationale
Practical, actionable regex guidance boosts analyst effectiveness; limited novelty and narrower scope to phishing triage.
Practice interview problems based on real data
1,500+ SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

