Course

Phishing Email Triage: From Message Evidence to Containment

Difficulty intermediate
Modules 3
Language en
Phishing Email TriageAn evidence path connects message preservation, authentication, content analysis, scoping, and containment.PRACTICAL SECURITY OPERATIONSPhishing Email TriageMessageIdentityContentScopeEVIDENCE → REASONING → DEFENSIBLE ACTION

About this course

Built for service-desk responders, SOC analysts, and security generalists who handle suspicious messages, this course teaches a repeatable investigation that starts with preserved evidence and ends with proportionate action. Learners examine sender identities, Received fields, SPF, DKIM, DMARC, URLs, attachments, delivery scope, and user interaction without treating any single signal as a verdict. The course emphasizes safe handling, evidence limits, escalation boundaries, and concise case notes. Completion means the learner can triage a reported message, explain what the evidence proves and does not prove, identify affected recipients and interactions, and recommend containment without live-clicking attacker content or overstating confidence.

What you'll learn

  • Preserve and inspect a suspicious message without activating links, attachments, or remote content.
  • Interpret routing, identity, SPF, DKIM, and DMARC evidence without confusing authentication with harmlessness.
  • Evaluate URLs and attachments using controlled analysis boundaries and corroborating evidence.
  • Scope recipients and interactions, select a defensible disposition, and document proportionate containment.

Course Content