All playbooks
SOC · SOC analysts and email security teams
Reported phishing message
Review a reported message, find other recipients and route the response.
Keep the original message and delivery context together; a forwarded screenshot is not enough to scope the campaign.
What this does not establish
- A suspicious sender name does not prove delivery or compromise.
- A clicked link does not establish credentials were entered.
- A single report does not reveal every recipient.
0 of 8 ticked
Selected step
FrameStep 1 of 8
Use the original message or a secure report artifact.
Capture headers and message identifiers
- Preserve Message-ID, sender, recipient, timestamps and delivery status.
- Handle attachments and URLs through approved safe analysis tools.