Scope Exposure, Choose a Disposition, and Write the Case
Find related delivery and interaction, distinguish message risk from incident impact, and record evidence-linked containment.
In this lesson, you will learn to:
- Scope related messages, recipients, and interaction using stable evidence.
- Write a disposition that links observations to confidence, containment, and follow-up.
Scope Exposure, Choose a Disposition, and Write the Case
Synthesizes the course into a complete triage: cluster related mail, assess clicks and credential use, select action, and produce concise case notes.
Expand from one message to the affected population
Start with stable pivots: Internet Message-ID, sender and envelope domains, connecting IP at the trusted boundary, attachment hash, normalized URL host and path, subject pattern, and delivery time. Search the mail platform for exact matches, then controlled variants. Attackers personalize recipients, subjects, URLs, and attachments, so no single query proves completeness. Record query fields, time range, returned count, delivery states, and retention limits. Determine who received, opened, clicked, downloaded, submitted credentials, approved a prompt, or executed a file using mail, proxy, identity, and endpoint evidence.
Interaction evidence must be time-aligned. A URL click after the message arrived is relevant; a DNS lookup alone may be caused by a scanner; an authentication event may be ordinary unless its device, location, method, and session context differ from the user’s pattern. If credentials may have been entered, scope subsequent sign-ins, token use, mailbox rules, forwarding, consent grants, and endpoint activity according to the response playbook. Contain the observed risk: remove delivered messages, block precise indicators, revoke sessions, reset credentials, or isolate a device only with appropriate authority.
Separate observations, judgments, actions, and open questions
Use a disposition vocabulary the team defines, such as malicious, suspicious, benign, or insufficient evidence. Then write why. Separate facts from assessments: “DMARC passed for an aligned domain” is an observation; “the sender’s account was likely compromised” is an assessment requiring supporting evidence. State confidence and the strongest alternative explanation. Record affected entities, timeline, interaction, containment performed, control owners, and what remains unverified.
A strong closure note is reproducible. Another analyst can see the original identifier, follow the pivots, understand why broad or narrow containment was selected, and reopen the case if new telemetry arrives. Avoid dumping every header field. Include only the evidence that changes the decision, plus links to preserved artifacts. Feed durable lessons back to defenses: a new detection, safer mail rule, user-reporting improvement, or gap in logging. Closing a message without scoping is premature; keeping a case open without a decision question is equally unhelpful.
Resources
- Microsoft email analysis in investigations — Review how related messages are clustered by sender and content attributes and how delivery location affects remediation decisions.