CYBERSECURITY
Phishing Investigation Guide
A safe, analyst-oriented workflow for evaluating a reported suspicious email without treating every message as malicious.
Preserve the report
Keep the original message and metadata available through approved systems. Do not forward suspicious attachments casually.
Review sender and routing context
Check display name, sender address, domains, authentication results and relevant headers using approved tooling.
Inspect links safely
Compare visible text with destinations and use approved reputation/sandbox systems rather than clicking suspicious links directly.
Assess attachments
Use organizational security tooling and policy. Do not open unknown files on a normal workstation merely to test them.
Determine scope
Search for similar messages, recipients, clicks, sign-ins, endpoint alerts, or related indicators where authorized.
Document and escalate
Record evidence, conclusion, scope, containment actions, and escalation based on the incident process.
KEEP BUILDING
Turn this topic into a skill
Use TechLoomix's career tools, technical calculators, learning paths, and related guides to practice what you learned.