Investigating Phishing Email Incident

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.

Njones17 Updated

File contents

Njones17/AI-agent-master-cyber-skills-list/tree/main/skills/incident-response/investigating-phishing-email-incident commit 917ba82ce8

Frequently asked questions

npx skillmds@latest add njones17/investigating-phishing-email-incident