How to Analyse a Phishing Email Like a SOC Analyst
A SOC-style phishing analysis preserves the original message, reads authentication and routing headers, inspects links and attachments safely (no casual detonation on your laptop), checks reputation, decides phish / spam / false positive, then contains and documents. Stay high-level and defensive — this is triage discipline, not malware reverse-engineering.
Friends, a user says "this mail looks suspicious". A SOC analyst does not panic — they follow a process. Preserve → headers → links/files in safe tools → reputation → decision → ticket. Today that beginner flow as a vertical list.
मित्रांनो, user म्हणतो "ही पत्रव्यवहार संशयास्पद आहे". SOC विश्लेषक घाबरत नाही – प्रक्रिया पाळतो. जतन → शीर्षके → दुवे/फाईल्स सुरक्षित साधनांत → प्रतिष्ठा → निर्णय → तिकीट. आज तोच नवशिक्या प्रवाह उभ्या यादीत.
मित्रों, user कहता है "यह पत्र संदिग्ध है". SOC विश्लेषक घबराता नहीं – प्रक्रिया अपनाता है. सुरक्षित रखें → शीर्षक → कड़ियाँ/फ़ाइलें सुरक्षित औज़ारों में → प्रतिष्ठा → निर्णय → टिकट. आज वही शुरुआती प्रवाह ऊर्ध्व सूची में.
Quick answer
Triage order:
- Preserve the original email (full headers /
.eml), not only a screenshot. - Note reporter, time received, and whether anyone already clicked.
- Read
From,Reply-To,Return-Path,Receivedchain, and auth results (SPF/DKIM/DMARCif present). - Extract URLs and file names without opening them on a production laptop.
- Check reputation with your approved tools (browser isolation, URL scanner, sandbox).
- Decide: phishing / spam / legitimate / inconclusive.
- Contain (block sender/URL, reset creds if clicked), notify stakeholders, write the ticket.
Analyst notepad template:
Case ID:
Reporter:
Subject:
From / Reply-To / Return-Path:
Auth results (SPF DKIM DMARC):
URL / attachment hashes (from safe tool):
Clicked? (yes/no/unknown):
Decision + actions:
What do I need before this guide?
- Access to a sample phishing mail in a lab mailbox (or a vendor “phishing quiz” sample).
- Your organisation’s safe-browsing / sandbox procedure if at work.
- Optional: What is phishing and SPF/DKIM/DMARC.
What does the SOC phishing flow look like?
SOC phishing triage: preserve the email, read headers, inspect links safely, check reputation, then contain and document the decision.
SOC फिशिंग check: पत्र जतन करा, शीर्षके वाचा, दुवे सुरक्षितपणे पाहा, प्रतिष्ठा पाहा, मग रोखा आणि निर्णय नोंदवा.
SOC फ़िशिंग check: पत्र सुरक्षित रखो, शीर्षक पढ़ो, कड़ियाँ सुरक्षित देखो, प्रतिष्ठा देखो, फिर रोकथाम करो और निर्णय लिखो.
- Preserve evidence so headers stay intact.
- Understand who sent it and how it arrived.
- Inspect indicators safely.
- Decide and contain.
- Record lessons for detection engineering (mail rules, blocks, user awareness).
How do I analyse the email step by step?
Step 1 — Preserve and ask the click question
- Save as
.emlor use “show original” / “view headers” export. - Ask: did anyone click, open an attachment, or enter a password?
- If yes, start password resets and session revocation in parallel (see IR guide).
Step 2 — Header reading (high level)
- Compare display name with the actual From domain.
- Check
Reply-Tofor a mismatch trap. - Skim the
Receivedpath for odd geography relative to the claimed brand (heuristic only). - Read Authentication-Results for SPF / DKIM / DMARC when present.
- Remember: pass does not always mean “safe” (compromised real accounts exist); fail does not always mean “drop without review”.
Step 3 — Links and attachments without detonating on your PC
- Copy URLs into your approved detonation / rewrite tool — not into your daily browser profile.
- Record final domains after redirects (from the tool’s report).
- For attachments, use a sandbox or a disposable lab VM with no corporate SSO session.
- Note file type tricks (double extensions, HTML smuggling) at a descriptive level only.
Step 4 — Reputation and context
- Check domain age / categorisation with approved intel sources.
- Search your SIEM / mailbox search for the same subject or sender (campaign?).
- Compare with brand-new vendor announcements using out-of-band channels.
Step 5 — Decision, containment and documentation
- Label the case (phish / spam / legit / needs more data).
- Block indicators per your playbook (mail filter, proxy, firewall).
- If credentials may be exposed: force reset, revoke tokens, review mailbox rules.
- Close the ticket with clear timeline and artefacts (headers hash, screenshots of tool output).
- Feed one improvement (user banner, block rule, awareness tip).
Ravindra Bagale's Tip
💡 Opening a phishing link on the analyst laptop to "check" it is a common mistake — corporate session cookie risk. Use a safe tool or isolated browser. And a screenshot alone is not evidence — keep the original .eml. Remember this!
Ravindra Bagale's Tip – मराठी
💡 Analyst laptop वर phishing link उघडून "check" – common चूक. Corporate session cookies risk. Safe tool / isolated browser वापरा. आणि screenshot only evidence नाही – original .eml ठेवा. लक्षात ठेवा!
Ravindra Bagale's Tip – हिंदी
💡 Analyst laptop पर phishing link खोलकर "check" – आम गलती. Corporate session cookies का risk. Safe tool / isolated browser इस्तेमाल करो. और सिर्फ screenshot evidence नहीं – original .eml रखो. याद रखो!
How do I fix common phishing-triage mistakes?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Only a screenshot in the ticket | User forwarded wrongly | Ask for original / “show original”; educate reporters |
| Marked safe because SPF passed | Compromised mailbox send | Still inspect links; contact purported sender out-of-band |
| Opened attachment locally | No sandbox habit | Use lab VM / vendor sandbox only |
| No idea who clicked | Forgot to ask | Make “clicked?” the second question every time |
| Duplicate tickets | Campaign blast | Search subject/sender first; link cases |
Try it at home
Use a known fake sample from a phishing-awareness quiz (not a live attack mail). Fill the notepad template above with seven lines filled. Time yourself — aim for a calm 15-minute first pass.
Learn it properly
Got it? SOC phishing triage = preserve, headers, safe link/file check, reputation, decision, contain, document. "Did anyone click?" — never skip that question. Calm process > panic click.
समजलं का? SOC फिशिंग check = जतन, शीर्षके, सुरक्षित दुवा/फाईल check, प्रतिष्ठा, निर्णय, रोख, नोंद. कुणी क्लिक केलं का? – हा प्रश्न विसरू नका. शांत प्रक्रिया > घाईत क्लिक.
समझ में आया? SOC फ़िशिंग check = सुरक्षित रखना, शीर्षक, सुरक्षित कड़ी/फ़ाइल check, प्रतिष्ठा, निर्णय, रोकथाम, दस्तावेज़. किसी ने क्लिक किया? – यह सवाल मत भूलना. शांत प्रक्रिया > घबराहट में क्लिक.
Frequently asked questions
Why keep the .eml file?
Screenshots lose headers and authentication results that analysts need.
Does SPF pass mean the mail is safe?
Not always. Compromised real accounts can still pass SPF. Keep inspecting links and context.
Should I open the suspect link on my laptop?
No. Use an approved sandbox or isolated browser without corporate sessions.
What is the second question after “what is the subject”?
Did anyone click, open an attachment, or enter a password?
What goes in the ticket?
Timeline, headers summary, indicators, decision, containment actions and follow-ups.
Which related guides help?
Phishing basics, SPF/DKIM/DMARC and the incident response first-24-hours guide.