Construction of Early Notification Framework to Anticipate Clone Phishing using GoPhish and Wazuh to Increase Blue Team's Detection Speed
DOI:
https://doi.org/10.59261/jequi.v8i4.408Keywords:
API Polling, Clone Phishing, GoPhish, Mean Time to Detect, Wazuh SIEMAbstract
Background: Clone phishing can exploit trusted message formats and user behavior, while delayed event ingestion into a SIEM can prolong the interval during which a Blue Team remains unaware of a credential-compromise attempt. This study addresses the operational gap between phishing simulation events and automated security monitoring.
Objective: This study develops and evaluates an early-notification framework that integrates Gophish, Wazuh SIEM, API-based event forwarding, and Telegram notifications, with the measurable objective of reducing phishing-event detection latency relative to manual event injection.
Methods: A controlled comparative experiment was conducted in a Docker-based simulation environment using Gophish, MailHog, a Python API-polling engine, Wazuh SIEM, a Python integrator, and a Telegram bot. Manual Injection served as the baseline, while API Polling Forwarding served as the proposed mechanism. Detection latency was operationalized as the interval from the Gophish click timestamp to the Wazuh detection timestamp; Telegram delivery occurred after detection and was therefore not included in the mean time to detection (MTTD).
Results: The aggregate comparison reported in the experiment showed an average detection latency of 72.60 seconds for Manual Injection and 3.73 seconds for API Polling Forwarding, corresponding to a 94.86% reduction in mean detection latency and a mean-detection-latency ratio of 19.46. These figures describe detection latency, not notification-delivery latency.
Conclusion: Automated API-based forwarding substantially reduced the observed detection latency between Gophish and Wazuh and enabled automated post-detection notification to the Blue Team. Because polling introduces an interval-dependent delay, the framework is appropriately characterized as near-real-time rather than real-time.
Downloads
References
Batu, A. D. A. H., & Hasan, Y. A. (2026). Aspek Krimonologi Terhadap Penipuan Online Pada Transaksi Phishing Di Wilayah Hukum Kepolisian Resor Kota Besar Makassar. Indonesian Journal Of Legality Of Law, 8(2), 229–235.
Bethany, M., Galiopoulos, A., Bethany, E., Karkevandi, M. B., Beebe, N., Vishwamitra, N., & Najafirad, P. (2025). Lateral Phishing With Large Language Models: A Large Organization Comparative Study. IEEE Access.
Business, V. (2024). 2024 Data Breach Investigations Report. Verizon Business. Https://Www.Verizon.Com/Business/Resources/Reports/Dbir/
Chen, L. C., Pardeshi, M. S., Liao, Y. X., & Pai, K. C. (2025). Application Of Retrieval-Augmented Generation For Interactive Industrial Knowledge Management Via A Large Language Model. Computer Standards & Interfaces, 94, 103995.
Cybersecurity, E. U. A. For. (2025). Enisa Threat Landscape 2025. European Union Agency For Cybersecurity. https://www.Enisa.Europa.Eu/Publications/Enisa-Threat-Landscape-2025
Farrel, F. I., Mardianto, I., & Qamar, A. S. (2024). Implementation Of Security Information & Event Management (Siem) Wazuh With Active Response And Telegram Notification For Mitigating Brute Force Attacks On The Gt-I2ti Usakti Information System. Intelmatics, 4(1), 1–7. https://doi.org/10.25105/Itm.V4i1.18529
Fitrian, H. P., Waryani, W., & Kirana, N. R. (2024). Analisis Keamanan Jaringan Komputer Terhadap Ancaman Phising Pada Pengguna E-Commerce. Jurnal Nasional Komputasi Dan Teknologi Informasi, 7(6), 2347–2354. https://doi.org/10.32672/Jnkti.V7i6.8388
Goldenits, G., König, P., Raubitzek, S., & Ekelhart, A. (2026). Small Language Models For Phishing Website Detection: Cost, Performance, And Privacy Trade-Offs. Journal Of Cybersecurity And Privacy, 6(2), 48.
Group, A.-P. W. (2025). Phishing Activity Trends Report: 1st Quarter 2025. Anti-Phishing Working Group. https://docs.Apwg.Org/Reports/Apwg_Trends_Report_Q1_2025.Pdf
Gumay, B., Hendrawan, A. H., & Kusumah, F. S. F. (2024). Analisis Dampak Ancaman Cybercrime Terhadap Data Mahasiswa Pada Serangan Web Phising Siak Uika. Infotech Journal, 10(2), 297–305. https://doi.org/10.31949/Infotech.V10i2.11463
Hartanto, B. D., Nugraha, T. A., Ramadhan, B. R., Pratama, M. A., & Alamsyah, R. P. (2025). Edukasi Keamanan Digital Untuk Meningkatkan Kewaspadaan Masyarakat Terhadap Link Phising. Jurnal Pengabdian Sosial, 2(9), 4341–4346. https://doi.org/10.59837/Nndaqp49
Hillman, D., Harel, Y., & Toch, E. (2023). Evaluating Organizational Phishing Awareness Training On An Enterprise Scale. Computers & Security, 132, 103364. https://doi.org/10.1016/J.Cose.2023.103364
Jayatilaka, A., Arachchilage, N. A. G., & Babar, M. A. (2021). Falling For Phishing: An Empirical Investigation Into People’s Email Response Behaviors. In Proceedings Of The 42nd International Conference On Information Systems (Icis 2021). Association For Information Systems. https://Aisel.Aisnet.Org/Icis2021/Cyber_Security/Cyber_Security/1/
Jumiaty, & Soewito, B. (2024). Siem And Threat Intelligence: Protecting Applications With Wazuh And Thehive. International Journal Of Advanced Computer Science And Applications, 15(9), 239–251. https://doi.org/10.14569/Ijacsa.2024.0150923
Kemp, S. (2025). Digital 2025: Indonesia. Datareportal. https://Datareportal.Com/Reports/Digital-2025-Indonesia
Lain, D., Kostiainen, K., & Capkun, S. (2022). Phishing In Organizations: Findings From A Large-Scale And Long-Term Study. In 2022 IEEE Symposium On Security And Privacy (Sp) (Pp. 842–859). IEEE. https://doi.org/10.1109/Sp46214.2022.9833766
Parhusip, J., Zahra, F. U. H., Monalisa, A., Kurniawan, M. R., & Lowryanty, N. P. (2026). Analisis Tingkat Kesadaran Mahasiswa Terhadap Keamanan Data Pribadi Di Era Digital: Studi Komparatif Antara Mahasiswa Teknik Informatika Dan Non-Teknik Informatika. Riggs: Journal Of Artificial Intelligence And Digital Business, 4(4), 8091–8101. https://doi.org/10.31004/Riggs.V4i4.4516
Rozema, A. T., & Davis, J. C. (2025). Anti-Phishing Training (Still) Does Not Work: A Large-Scale Reproduction Of Phishing Training Inefficacy Grounded In The Nist Phish Scale. Arxiv Preprint Arxiv:2506.19899.
Sirawongphatsara, P., Pornpongtechavanich, P., Phanthuna, N., & Daengsi, T. (2025). Comparative Simulation Of Phishing Attacks On A Critical Information Infrastructure Organization: An Empirical Study. Bulletin Of Electrical Engineering And Informatics, 14(2), 1526–1534. https://doi.org/10.11591/Eei.V14i2.8020
Srivastava, P., & Mukhopadhyay, A. (2026). Cyber-Risk Assessment And Mitigation Framework For Critical Information Infrastructure: Mixed-Methods Approach. Journal Of Enterprise Information Management, 1–27.
Syah, R. (2023). Strategi Kepolisian Dalam Pencegahan Kejahatan Phising Melalui Media Sosial Di Ruang Siber. Jurnal Impresi Indonesia, 2(9), 864–870. https://doi.org/10.58344/Jii.V2i9.3594
Wang, R. C., Chen, M. C., Chang, K. T., & Hsueh, T. Y. (2026). Spai Phishing: A Design And Evaluation Of Ai-Assisted Large Spear Phishing Cybersecurity Drill. Systems And Soft Computing, 200518.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Jeremy Pierre Tumbio, Benfano Soewito

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.




