A little learning. A little more confidence.Your next step starts here

SOC Analyst · Lesson 4 of 8

Investigating a reported message

A reported email is evidence to handle carefully. The task is to assess its request and available indicators without exposing yourself or others to its contents.

SEE THE IDEA

Separate the kinds of interaction

A fictional user reports a suspicious reset message.

Separate the kinds of interaction
InteractionWhat is knownNext consideration
Received the messageConfirmed by reportPreserve the message and approved metadata
Clicked the linkUser reports yesRecord the statement and investigate exposure
Entered credentialsUser reports noDo not relabel a click as credential submission
Downloaded a fileNot yet establishedAsk a focused follow-up question
These are separate facts to establish, not an inevitable sequence. Follow the approved response process.
Read the visualCan you write “credentials stolen” from this report?

No. Record the reported interaction and uncertainty, then seek supporting evidence.

Preserve the report

Keep the original report and approved message metadata. Record who reported it and when without spreading unnecessary personal data.

Inspect safely

Compare the sender, claimed organization, and displayed destination using approved tools. Do not open unknown attachments or submit private files to public services.

Separate exposure from impact

Receiving a message, clicking a link, and entering credentials are different events. Ask focused questions through a trusted channel.

Put it in context

A user reports a message asking for a password reset. They say they clicked but did not enter credentials. Record that statement and seek relevant sign-in evidence.

Record what happened to the recipient, not just what the message requested.

Read the sources

Make it stick.

Try one short question to check your understanding and save this lesson to your progress.

YOUR LEARNING SPACE