Investigating Phishing Email Incident

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.

26zl Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/investigating-phishing-email-incident commit c3da70bfb4

Frequently asked questions

npx skillmds@latest add 26zl/investigating-phishing-email-incident