Module
Email & Phishing Investigation
Take a user-reported email and, without clicking anything, say where it really came from, whether its link or attachment is hostile, who else received it and who acted on it. Then remove it from every inbox and block the sender so the second wave bounces.
66 min · Beginner
Start Email & Phishing Investigation
What you will learn
- Get the original of a reported email and name the IP your own gateway accepted it from
- Read SPF, DKIM and DMARC results and say what a pass does and does not prove
- Find where a link really goes without your own browser ever visiting it
- Identify an attachment by its content, hash it, and read where it sends the password
- Find every recipient, click and typed password, then remove, block, reset, report and write it up
Lessons
Where It Really Came From
The From address is a header the sender typed. The connecting IP and the Return-Path are what the mail system saw.
Reading the Authentication Results
SPF, DKIM and DMARC prove the domain in the header sent the message. When the attacker owns that domain, every check passes.
Follow the Link Without Clicking It
The link text is not the link. Unwrap it, read the hostname right to left, and let a sandbox do the visiting.
The Attachment Is Not What It Is Called
Identify a file by its content, hash it, and know that not found is not clean.
Who Got It, Who Clicked, and Shutting It Down
The reporter is one of 184. Find the rest, the clicks and the typed passwords, then shut the campaign down and write the page.