Employee Sarah Miller (Finance Dept.) forwarded a suspicious email she received at 09:12 UTC today. She reported that it appeared to be from Microsoft IT Security but something felt "off" about the link. She did not click the link and did not open the attachment. The email has been quarantined pending your analysis.
You are the on-call SOC analyst. You must triage this email, identify all Indicators of Compromise (IOCs), determine whether it is a phishing attempt, and complete an Incident Response report for escalation.
| Tool | Purpose |
|---|---|
| Email Client | View the suspicious email + full headers |
| Header Analyzer | Parse and flag suspicious header fields |
| URL Inspector | Safely detonate and analyze links |
| Threat Intel | Look up IPs and domains against threat feeds |
| Terminal | whois, dig, nslookup on suspicious domains |
| IR Report | Document findings and recommend actions |