Phishing Analysis

Analyze a reported or suspicious email end to end: Received chain and SPF/DKIM/DMARC alignment, sender and Reply-To and display-name mismatches, lookalike domains, URL and redirector analysis, QR codes, HTML smuggling, attachment triage, lure classification (BEC/invoice, credential harvest, callback/TOAD, MFA push, package delivery, HR/payroll), verdict, blast radius, and response actions. Use it whenever someone pastes headers or an .eml, says "is this phishing", "a user reported this email", "check these headers", "is this sender legit", "who else got this", asks why DMARC failed, wants a phishing triage note, or forwards a suspicious invoice, voicemail, DocuSign, MFA, delivery, or payroll-change message, even if they never use the word phishing.

ftrout Updated

File contents

ftrout/secops-claude-skills/tree/main/skills/phishing-analysis commit 76e71ce54f

Frequently asked questions

npx skillmds@latest add ftrout/phishing-analysis