SOC Analyst · Lesson 4 of 8
Investigating a reported message
A reported email is evidence to handle carefully. The task is to assess its request and available indicators without exposing yourself or others to its contents.
Separate the kinds of interaction
A fictional user reports a suspicious reset message.
| Interaction | What is known | Next consideration |
|---|---|---|
| Received the message | Confirmed by report | Preserve the message and approved metadata |
| Clicked the link | User reports yes | Record the statement and investigate exposure |
| Entered credentials | User reports no | Do not relabel a click as credential submission |
| Downloaded a file | Not yet established | Ask a focused follow-up question |
Read the visualCan you write “credentials stolen” from this report?
No. Record the reported interaction and uncertainty, then seek supporting evidence.
Preserve the report
Keep the original report and approved message metadata. Record who reported it and when without spreading unnecessary personal data.
Inspect safely
Compare the sender, claimed organization, and displayed destination using approved tools. Do not open unknown attachments or submit private files to public services.
Separate exposure from impact
Receiving a message, clicking a link, and entering credentials are different events. Ask focused questions through a trusted channel.
Put it in context
A user reports a message asking for a password reset. They say they clicked but did not enter credentials. Record that statement and seek relevant sign-in evidence.
Record what happened to the recipient, not just what the message requested.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.