Phishing Mail Investigation
Phishing investigation Phishing is a cybercrime in which a target or targets are contacted by email, telephone or text message by someone posing as a legitimate institution to lure individuals into providing sensitive data such as personally identifiable information, banking and credit card details, and passwords. In SIEM investigation. Phishing mails reports us 1. Customers 2. Employees or 3. We get alert In SIEM tool. The investigation following Firstly we requested to employee or customers to send saved email. Once we receive mail à We have to save mail Go to properties. Copy the complete in Internet Header information Then we have Threat Intelligence tool Mx tool Box open In Header Analyzer Then Paste In Header analyzer part.. Need to check Following point 1. SPF : sender policy Framework Find the Original Sender ip address then check reputation of this from various Thr...