Investigating a Phishing Email
Section IntroductionX
Artifacts to Collect
Email Artifacts
Sending Email Address
Subject Line
Recipient Email Addresses
Sending Server IP & Reverse DNS
Reply-To Address
Date & Time
File Artifacts
Attachment Name
SHA256 Hash Value
Web Artifacts
Full URLs
Root Domain
Manual Collection - Email Artifacts
Email Artifact List
Email Client Extraction
Text Editor Extraction
Manual Collection - Web Artifacts
Email Client Extraction
Text Editor Extraction
Manual Collection - File Artifacts
Hashes via PowerShell
Hashes via Linux CLI
Automated Collection With PhishTool
Example One
Example Two
Last updated