Please use this identifier to cite or link to this item:
https://ric.cps.sp.gov.br/handle/123456789/46618| Title: | Automatização das ferramentas de phishing e seus impactos |
| Other Titles: | Automation of phishing tools and their impacts |
| Authors: | BARTELLI, Gabriel Henrique RAIMUNDO, Vitor Barbosa |
| Advisor: | BERGAMASCO, Daives Arakem |
| Other contributor: | CORRÊA, Rafael Vinícius Costa CRUZ, Benedito Aparecido |
| type of document: | Monografia |
| Keywords: | Engenharia;Inteligência artificial;Segurança de redes |
| Issue Date: | 9-Jun-2026 |
| Publisher: | 004 |
| Citation: | BARTELLI, Gabriel Henrique; RAIMUNDO, Vitor Barbosa. Automatização das ferramentas de phishing e seus impactos , 2026. Trabalho de conclusão de curso (Curso Superior de Tecnologia em Segurança da Informação) - Faculdade de Tecnologia de Americana "Ministro Ralph Biasi", Americana, 2026. |
| Abstract: | Este trabalho analisa a automatização das ferramentas de phishing e seus impactos
no contexto da segurança da informação, com foco na relação entre o uso de
inteligência artificial em campanhas ofensivas e as capacidades defensivas oferecidas
por arquiteturas de Security Orchestration, Automation and Response (SOAR). O
estudo parte da compreensão da engenharia social como ameaça sociotécnica, cuja
eficácia depende da articulação entre persuasão, exploração do comportamento
humano e infraestrutura digital. A pesquisa tem como objetivo geral examinar de que
forma a automação amplia a escala, a sofisticação e o potencial de dano do phishing,
bem como discutir em que medida soluções SOAR contribuem para a detecção,
triagem e resposta automatizada a esse tipo de incidente. Metodologicamente,
caracteriza-se como pesquisa exploratória e descritiva, de abordagem qualitativa,
desenvolvida por meio de revisão bibliográfica e documental. Foram analisados livros,
artigos científicos, relatórios técnicos e documentações institucionais relacionados à
engenharia social, phishing, inteligência artificial, automação defensiva e resposta a
incidentes. Os resultados indicam que a inteligência artificial tende a potencializar o
phishing ao reduzir erros linguísticos, ampliar a personalização de mensagens,
acelerar a produção de iscas e permitir campanhas em maior escala. Em
contrapartida, o SOAR contribui para reduzir a janela de exposição por meio da
orquestração de playbooks, enriquecimento automático de indicadores, integração
com ferramentas de segurança e padronização de respostas. Conclui-se que a
automação defensiva não neutraliza integralmente a escala proporcionada pela
inteligência artificial, mas constitui elemento essencial para aumentar a capacidade
de resposta, reduzir impactos operacionais e fortalecer a resiliência organizacional
diante de campanhas de phishing cada vez mais sofisticadas.
Palavras-chave: Engenharia social; Phishing; Inteligência artificial; SOAR;
Segurança da informação. This study analyzes the automation of phishing tools and its impacts in the field of information security, focusing on the relationship between the use of artificial intelligence in offensive campaigns and the defensive capabilities provided by Security Orchestration, Automation and Response (SOAR) architectures. The study understands social engineering as a sociotechnical threat whose effectiveness depends on the combination of persuasion, exploitation of human behavior and digital infrastructure. Its main objective is to examine how automation increases the scale, sophistication and potential damage of phishing, as well as to discuss the extent to which SOAR solutions contribute to automated detection, triage and response to this type of incident. Methodologically, the research is exploratory and descriptive, with a qualitative approach, developed through bibliographic and documentary review. Books, scientific articles, technical reports and institutional documents related to social engineering, phishing, artificial intelligence, defensive automation and incident response were analyzed. The results indicate that artificial intelligence tends to strengthen phishing by reducing linguistic errors, increasing message personalization, accelerating the production of lures and enabling campaigns on a larger scale. Conversely, SOAR contributes to reducing the exposure window through playbook orchestration, automatic enrichment of indicators, integration with security tools and response standardization. The study concludes that defensive automation does not fully neutralize the scale enabled by artificial intelligence, but it is an essential element for increasing response capacity, reducing operational impacts and strengthening organizational resilience against increasingly sophisticated phishing campaigns. Keywords: Social engineering; Phishing; Artificial intelligence; SOAR; Information security. |
| URI: | https://ric.cps.sp.gov.br/handle/123456789/46618 |
| Appears in Collections: | Trabalhos de Conclusão de Curso |
Files in This Item:
| File | Description | Size | Format | |
|---|---|---|---|---|
| 20261S_Gabriel Henrique Bartelli_OD2955.pdf Restricted Access | 882.74 kB | Adobe PDF | View/Open Request a copy | |
| Termos de Autorização - Gabriel; Vitor.pdf Restricted Access | 2.18 MB | Adobe PDF | View/Open Request a copy |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.