Investigating Phishing Email Incident

Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.

theheavenlyd3mon 3d088ca 4 files · 31.5 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-forensics/skills/Anthropic-Cybersecurity-Skills/skills/investigating-phishing-email-incident commit 3d088ca44f

Frequently asked questions

npx skillmds add theheavenlyd3mon/investigating-phishing-email-incident