Please use this identifier to cite or link to this item: https://ric.cps.sp.gov.br/handle/123456789/46618
Title: Automatização das ferramentas de phishing e seus impactos
Other Titles: Automation of phishing tools and their impacts
Authors: BARTELLI, Gabriel Henrique
RAIMUNDO, Vitor Barbosa
Advisor: BERGAMASCO, Daives Arakem
Other contributor: CORRÊA, Rafael Vinícius Costa
CRUZ, Benedito Aparecido
type of document: Monografia
Keywords: Engenharia;Inteligência artificial;Segurança de redes
Issue Date: 9-Jun-2026
Publisher: 004
Citation: BARTELLI, Gabriel Henrique; RAIMUNDO, Vitor Barbosa. Automatização das ferramentas de phishing e seus impactos , 2026. Trabalho de conclusão de curso (Curso Superior de Tecnologia em Segurança da Informação) - Faculdade de Tecnologia de Americana "Ministro Ralph Biasi", Americana, 2026.
Abstract: Este trabalho analisa a automatização das ferramentas de phishing e seus impactos no contexto da segurança da informação, com foco na relação entre o uso de inteligência artificial em campanhas ofensivas e as capacidades defensivas oferecidas por arquiteturas de Security Orchestration, Automation and Response (SOAR). O estudo parte da compreensão da engenharia social como ameaça sociotécnica, cuja eficácia depende da articulação entre persuasão, exploração do comportamento humano e infraestrutura digital. A pesquisa tem como objetivo geral examinar de que forma a automação amplia a escala, a sofisticação e o potencial de dano do phishing, bem como discutir em que medida soluções SOAR contribuem para a detecção, triagem e resposta automatizada a esse tipo de incidente. Metodologicamente, caracteriza-se como pesquisa exploratória e descritiva, de abordagem qualitativa, desenvolvida por meio de revisão bibliográfica e documental. Foram analisados livros, artigos científicos, relatórios técnicos e documentações institucionais relacionados à engenharia social, phishing, inteligência artificial, automação defensiva e resposta a incidentes. Os resultados indicam que a inteligência artificial tende a potencializar o phishing ao reduzir erros linguísticos, ampliar a personalização de mensagens, acelerar a produção de iscas e permitir campanhas em maior escala. Em contrapartida, o SOAR contribui para reduzir a janela de exposição por meio da orquestração de playbooks, enriquecimento automático de indicadores, integração com ferramentas de segurança e padronização de respostas. Conclui-se que a automação defensiva não neutraliza integralmente a escala proporcionada pela inteligência artificial, mas constitui elemento essencial para aumentar a capacidade de resposta, reduzir impactos operacionais e fortalecer a resiliência organizacional diante de campanhas de phishing cada vez mais sofisticadas. Palavras-chave: Engenharia social; Phishing; Inteligência artificial; SOAR; Segurança da informação.
This study analyzes the automation of phishing tools and its impacts in the field of information security, focusing on the relationship between the use of artificial intelligence in offensive campaigns and the defensive capabilities provided by Security Orchestration, Automation and Response (SOAR) architectures. The study understands social engineering as a sociotechnical threat whose effectiveness depends on the combination of persuasion, exploitation of human behavior and digital infrastructure. Its main objective is to examine how automation increases the scale, sophistication and potential damage of phishing, as well as to discuss the extent to which SOAR solutions contribute to automated detection, triage and response to this type of incident. Methodologically, the research is exploratory and descriptive, with a qualitative approach, developed through bibliographic and documentary review. Books, scientific articles, technical reports and institutional documents related to social engineering, phishing, artificial intelligence, defensive automation and incident response were analyzed. The results indicate that artificial intelligence tends to strengthen phishing by reducing linguistic errors, increasing message personalization, accelerating the production of lures and enabling campaigns on a larger scale. Conversely, SOAR contributes to reducing the exposure window through playbook orchestration, automatic enrichment of indicators, integration with security tools and response standardization. The study concludes that defensive automation does not fully neutralize the scale enabled by artificial intelligence, but it is an essential element for increasing response capacity, reducing operational impacts and strengthening organizational resilience against increasingly sophisticated phishing campaigns. Keywords: Social engineering; Phishing; Artificial intelligence; SOAR; Information security.
URI: https://ric.cps.sp.gov.br/handle/123456789/46618
Appears in Collections:Trabalhos de Conclusão de Curso

Files in This Item:
File Description SizeFormat 
20261S_Gabriel Henrique Bartelli_OD2955.pdf
  Restricted Access
882.74 kBAdobe PDFView/Open Request a copy
Termos de Autorização - Gabriel; Vitor.pdf
  Restricted Access
2.18 MBAdobe PDFView/Open Request a copy


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.