Construction of Early Notification Framework to Anticipate Clone Phishing using GoPhish and Wazuh to Increase Blue Team's Detection Speed

Authors

  • Jeremy Pierre Tumbio Universitas Bina Nusantara
  • Benfano Soewito Universitas Bina Nusantara

DOI:

https://doi.org/10.59261/jequi.v8i4.408

Keywords:

API Polling, Clone Phishing, GoPhish, Mean Time to Detect, Wazuh SIEM

Abstract

Background: Clone phishing can exploit trusted message formats and user behavior, while delayed event ingestion into a SIEM can prolong the interval during which a Blue Team remains unaware of a credential-compromise attempt. This study addresses the operational gap between phishing simulation events and automated security monitoring.

Objective: This study develops and evaluates an early-notification framework that integrates Gophish, Wazuh SIEM, API-based event forwarding, and Telegram notifications, with the measurable objective of reducing phishing-event detection latency relative to manual event injection.

Methods: A controlled comparative experiment was conducted in a Docker-based simulation environment using Gophish, MailHog, a Python API-polling engine, Wazuh SIEM, a Python integrator, and a Telegram bot. Manual Injection served as the baseline, while API Polling Forwarding served as the proposed mechanism. Detection latency was operationalized as the interval from the Gophish click timestamp to the Wazuh detection timestamp; Telegram delivery occurred after detection and was therefore not included in the mean time to detection (MTTD).

Results: The aggregate comparison reported in the experiment showed an average detection latency of 72.60 seconds for Manual Injection and 3.73 seconds for API Polling Forwarding, corresponding to a 94.86% reduction in mean detection latency and a mean-detection-latency ratio of 19.46. These figures describe detection latency, not notification-delivery latency.

Conclusion: Automated API-based forwarding substantially reduced the observed detection latency between Gophish and Wazuh and enabled automated post-detection notification to the Blue Team. Because polling introduces an interval-dependent delay, the framework is appropriately characterized as near-real-time rather than real-time.

Downloads

Download data is not yet available.

References

Batu, A. D. A. H., & Hasan, Y. A. (2026). Aspek Krimonologi Terhadap Penipuan Online Pada Transaksi Phishing Di Wilayah Hukum Kepolisian Resor Kota Besar Makassar. Indonesian Journal Of Legality Of Law, 8(2), 229–235.

Bethany, M., Galiopoulos, A., Bethany, E., Karkevandi, M. B., Beebe, N., Vishwamitra, N., & Najafirad, P. (2025). Lateral Phishing With Large Language Models: A Large Organization Comparative Study. IEEE Access.

Business, V. (2024). 2024 Data Breach Investigations Report. Verizon Business. Https://Www.Verizon.Com/Business/Resources/Reports/Dbir/

Chen, L. C., Pardeshi, M. S., Liao, Y. X., & Pai, K. C. (2025). Application Of Retrieval-Augmented Generation For Interactive Industrial Knowledge Management Via A Large Language Model. Computer Standards & Interfaces, 94, 103995.

Cybersecurity, E. U. A. For. (2025). Enisa Threat Landscape 2025. European Union Agency For Cybersecurity. https://www.Enisa.Europa.Eu/Publications/Enisa-Threat-Landscape-2025

Farrel, F. I., Mardianto, I., & Qamar, A. S. (2024). Implementation Of Security Information & Event Management (Siem) Wazuh With Active Response And Telegram Notification For Mitigating Brute Force Attacks On The Gt-I2ti Usakti Information System. Intelmatics, 4(1), 1–7. https://doi.org/10.25105/Itm.V4i1.18529

Fitrian, H. P., Waryani, W., & Kirana, N. R. (2024). Analisis Keamanan Jaringan Komputer Terhadap Ancaman Phising Pada Pengguna E-Commerce. Jurnal Nasional Komputasi Dan Teknologi Informasi, 7(6), 2347–2354. https://doi.org/10.32672/Jnkti.V7i6.8388

Goldenits, G., König, P., Raubitzek, S., & Ekelhart, A. (2026). Small Language Models For Phishing Website Detection: Cost, Performance, And Privacy Trade-Offs. Journal Of Cybersecurity And Privacy, 6(2), 48.

Group, A.-P. W. (2025). Phishing Activity Trends Report: 1st Quarter 2025. Anti-Phishing Working Group. https://docs.Apwg.Org/Reports/Apwg_Trends_Report_Q1_2025.Pdf

Gumay, B., Hendrawan, A. H., & Kusumah, F. S. F. (2024). Analisis Dampak Ancaman Cybercrime Terhadap Data Mahasiswa Pada Serangan Web Phising Siak Uika. Infotech Journal, 10(2), 297–305. https://doi.org/10.31949/Infotech.V10i2.11463

Hartanto, B. D., Nugraha, T. A., Ramadhan, B. R., Pratama, M. A., & Alamsyah, R. P. (2025). Edukasi Keamanan Digital Untuk Meningkatkan Kewaspadaan Masyarakat Terhadap Link Phising. Jurnal Pengabdian Sosial, 2(9), 4341–4346. https://doi.org/10.59837/Nndaqp49

Hillman, D., Harel, Y., & Toch, E. (2023). Evaluating Organizational Phishing Awareness Training On An Enterprise Scale. Computers & Security, 132, 103364. https://doi.org/10.1016/J.Cose.2023.103364

Jayatilaka, A., Arachchilage, N. A. G., & Babar, M. A. (2021). Falling For Phishing: An Empirical Investigation Into People’s Email Response Behaviors. In Proceedings Of The 42nd International Conference On Information Systems (Icis 2021). Association For Information Systems. https://Aisel.Aisnet.Org/Icis2021/Cyber_Security/Cyber_Security/1/

Jumiaty, & Soewito, B. (2024). Siem And Threat Intelligence: Protecting Applications With Wazuh And Thehive. International Journal Of Advanced Computer Science And Applications, 15(9), 239–251. https://doi.org/10.14569/Ijacsa.2024.0150923

Kemp, S. (2025). Digital 2025: Indonesia. Datareportal. https://Datareportal.Com/Reports/Digital-2025-Indonesia

Lain, D., Kostiainen, K., & Capkun, S. (2022). Phishing In Organizations: Findings From A Large-Scale And Long-Term Study. In 2022 IEEE Symposium On Security And Privacy (Sp) (Pp. 842–859). IEEE. https://doi.org/10.1109/Sp46214.2022.9833766

Parhusip, J., Zahra, F. U. H., Monalisa, A., Kurniawan, M. R., & Lowryanty, N. P. (2026). Analisis Tingkat Kesadaran Mahasiswa Terhadap Keamanan Data Pribadi Di Era Digital: Studi Komparatif Antara Mahasiswa Teknik Informatika Dan Non-Teknik Informatika. Riggs: Journal Of Artificial Intelligence And Digital Business, 4(4), 8091–8101. https://doi.org/10.31004/Riggs.V4i4.4516

Rozema, A. T., & Davis, J. C. (2025). Anti-Phishing Training (Still) Does Not Work: A Large-Scale Reproduction Of Phishing Training Inefficacy Grounded In The Nist Phish Scale. Arxiv Preprint Arxiv:2506.19899.

Sirawongphatsara, P., Pornpongtechavanich, P., Phanthuna, N., & Daengsi, T. (2025). Comparative Simulation Of Phishing Attacks On A Critical Information Infrastructure Organization: An Empirical Study. Bulletin Of Electrical Engineering And Informatics, 14(2), 1526–1534. https://doi.org/10.11591/Eei.V14i2.8020

Srivastava, P., & Mukhopadhyay, A. (2026). Cyber-Risk Assessment And Mitigation Framework For Critical Information Infrastructure: Mixed-Methods Approach. Journal Of Enterprise Information Management, 1–27.

Syah, R. (2023). Strategi Kepolisian Dalam Pencegahan Kejahatan Phising Melalui Media Sosial Di Ruang Siber. Jurnal Impresi Indonesia, 2(9), 864–870. https://doi.org/10.58344/Jii.V2i9.3594

Wang, R. C., Chen, M. C., Chang, K. T., & Hsueh, T. Y. (2026). Spai Phishing: A Design And Evaluation Of Ai-Assisted Large Spear Phishing Cybersecurity Drill. Systems And Soft Computing, 200518.

Downloads

Published

2026-09-10