Investigating Phishing Email Incident

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.

henriquescastilho Updated

File contents

henriquescastilho/my-claude/tree/main/.claude/skills/investigating-phishing-email-incident commit c3da70bfb4

Frequently asked questions

npx skillmds@latest add henriquescastilho/investigating-phishing-email-incident