Investigating Phishing Email Incident

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.

galyarderlabs Updated 20 repo stars

File contents

galyarderlabs/galyarder-framework/tree/main/skills/investigating-phishing-email-incident commit d4fbb81f08

Frequently asked questions

npx skillmds@latest add galyarderlabs/investigating-phishing-email-incident