Phishing Investigation & Email Threat Analysis
IntermediateLearn phishing investigation and email analysis: triage reported mail, read headers, SPF, DKIM and DMARC as evidence, scope the campaign, take the site down. Throughout the path you work a reported-phishing queue the way a SOC does, including the messages that turn out not to be attacks, take a lookalike domain and its credential capture page apart, and run the response on both sides of it: the people who received the message and the brand whose name it used. Four sections, ten modules, five hands-on missions, two of them on a live lab range and investigation surfaces, and the Phishing Triage simulator.

Curriculum
8 more steps behind a free account
Free account
Ready to start Phishing Investigation & Email Threat Analysis?
Create a free account to open the remaining 8 steps, track every one you finish and earn your certificate.
- Free to start
- Progress saved on every step
- Certificate on completion
Already have an account? Sign in
About this path
Most phishing reports are not attacks. A sign-in notice from a real service, a supplier moving its invoices to a new platform, a newsletter somebody forgot they subscribed to. The queue is full of mail that looks wrong and is fine. This path treats "not malicious" as a verdict you have to earn, with the mundane explanation named and the evidence pointed at, and it treats the reflex escalation as a cost rather than as the safe choice. Everything else in it is about the reports that are attacks, and about how far behind one message the work actually goes.
Every lesson hands you an artefact and asks for a decision. A header block, a URL, a gateway log extract, a takedown file. The order follows a real investigation. You collect before you change anything, read the message as evidence rather than as content, decide what the authentication results can and cannot settle, follow the link to the page and the kit behind it, scope the campaign across every mailbox it reached, and then run the response.
The first section covers the anatomy of a phishing message, how operators and phishing-as-a-service suppliers run a campaign, the targeting behind spear phishing, whaling, business email compromise and thread hijacking, and the triage decisions an analyst makes in the first five minutes. The second section is email as evidence: the envelope against the header, what each address field proves, the Received chain read from the bottom up, HTML bodies and attachments you should never open, and preserving the .eml with hashes and custody. It closes on SPF, DKIM and DMARC, and on why a message that passes all three can still be hostile.
The third section is the technical investigation. You read a URL before it resolves, recognise lookalike domains, find where a credential capture page sends what it collects, scope the campaign from gateway logs, and hunt a brand's lookalike domains through permutation, certificate transparency, urlscan and DNS pivots. The fourth section is the response. On the victim side you size the blast radius, choose containment by what each step costs and recover accounts after a session has already been stolen. On the brand side you build a takedown package a registrar or host will act on, and check that the page stays down.
Five missions run alongside the lessons. You triage a morning of reports and find the one that is not an attack, decide four messages whose authentication results cannot settle the verdict on their own, and work a supplier invoice that passes SPF and DKIM. In the capstone, Operation False Invoice, you fetch a capture page off the lab range, read the records behind its domains and run the response across a closed forum and a breach corpus. Between them, the Phishing Triage simulator asks for ten correct verdicts on a bank of real-looking mail, legitimate messages included.
There is no formal prerequisite. You should be comfortable reading raw text, a header block, a log line or a fragment of HTML, without a tool interpreting it for you. Cyber Threat Intelligence is a good path to take first. The graded work needs no vendor account or API key. The capture pages the missions send you to sit on the CTI Academy lab range, reached over the VPN configuration from Lab Access, and where a lesson works on real phishing domains it does so through public records such as certificate logs, DNS and urlscan rather than by opening the pages.
What you will learn
- Triage a reported message in the first five minutes. Decide what to open first, collect the evidence before anything changes it, and close, escalate or monitor with a reason you can write down.
- Call a benign message benign. Recognise the weird but legitimate mail every queue is full of, and defend a not malicious verdict instead of escalating by reflex.
- Read an email as evidence. Separate the envelope from the header, say what each address field actually proves, and read the Received chain from the bottom up to the first hop you can trust.
- Know what SPF, DKIM and DMARC actually settle. Read each authentication result for what it binds, spot a pass that proves nothing about the visible sender, and handle mail that authenticates and is still hostile.
- Take a phishing page apart without opening it. Read a URL before it resolves, recognise lookalike and brand-impersonating domains, and find where a credential capture page sends what it collects, including targets built at runtime.
- Use a phishing kit for what it is worth. Cluster campaigns and write detections from kit signatures and page artifacts, without mistaking the toolmaker's tag for the operator.
- Scope the campaign behind one message. Use gateway and mail logs to find every mailbox it reached, the earlier reconnaissance messages nobody reported, and the artefacts that will still be useful next week.
- Hunt lookalike domains before they are used. Combine permutation engines, certificate transparency, urlscan page artifacts and DNS pivots to find a brand's lookalikes and the infrastructure they share.
- Run the victim-side response in the right order. Size the blast radius from received to signed in, weigh what each containment step costs, and recover an account after a session has already been stolen.
- Get a phishing site taken down. Build a takedown package a registrar or host will act on, choose the right escalation path, and verify the page is gone and stays gone.
Who this path is for
- SOC analysts who work a reported-phishing queue and want a method behind the verdict, not another checklist of red flags.
- Incident responders who take over once credentials have been submitted and need to scope the campaign and contain it in the right order.
- Brand protection, fraud and threat intelligence analysts whose organisation's name keeps turning up on lookalike domains and credential capture pages.
- Anyone who has finished Cyber Threat Intelligence or Cybersecurity Foundations and wants a hands-on investigation path built around email.
Guides for this path
- Most Common Psychological Tactics Used in Social Engineering AttacksIn 2025, a threat group went from a single help-desk phone call to full domain administrator access in about forty minutes, without using any malware. This is what social engineering psychological tactics actually look like: authority, urgency, fear, and helpfulness, stacked together and aimed at the mental shortcuts that make normal professional life possible. Here is how each lever works, why training alone doesn't stop them, and the defenses that hold up under pressure.
Frequently asked questions
Collect before you change anything: save the original .eml with its full headers and hash it before anybody deletes or forwards the message. Then read the envelope against the header, trace the Received chain from the bottom up to the first hop you can trust, and weigh what the SPF, DKIM and DMARC results actually bind. Read the URL and the attachment as text instead of opening them, and only then scope, by searching the gateway and mail logs for every mailbox the message reached. The path is built in that order, and each lesson hands you the artefact for its step.
No. SPF says a server was allowed to send for the envelope domain, DKIM says a domain signed the message, and DMARC alignment is the only check that ties either of them to the From address a person actually reads. An attacker who registers a lookalike domain can pass all three for that domain, and a compromised supplier mailbox passes them for the genuine one. The Authentication and Trust module and the Authentication Trap mission are built around that gap between a passing result and a trustworthy sender.
Awareness training teaches the people who receive mail to spot red flags. This path is for the analyst who receives their reports. It covers the verdict, including the defensible decision that a message is not malicious, the evidence behind it, the scope of the campaign and the response, all the way to getting the lookalike domain and its page taken down.
No. The graded work needs no vendor account or API key. The artefacts are built for the path: headers, message bodies, attachments, gateway log extracts and whois records, and the capture pages in the capstone run on the CTI Academy lab range, reached over the VPN configuration from Lab Access. The domain discovery lessons use free public sources such as crt.sh, urlscan and ordinary DNS lookups.
There is no formal prerequisite. You should be comfortable reading raw text, a header block, a log line or a fragment of HTML, without a tool interpreting it for you. Cyber Threat Intelligence is a good path to take first if you want the wider picture of how phishing reports feed into intelligence work.
That is where the fourth section starts. On the victim side you size the blast radius from received to clicked, submitted and signed in, choose containment by what each step costs, and revoke sessions before anything else when a sign-in has already happened, because a password reset alone does not end a session that has been stolen. On the brand side you build a takedown package a registrar or host will act on, escalate through the right provider and verify the page stays down.
Four sections, ten modules of short lessons with quizzes, five hands-on missions and the Phishing Triage simulator, roughly nine hours at a normal pace. The simulator step asks for ten correct verdicts on a bank of real-looking mail, legitimate messages included. Completing every step earns the path certificate.