Analyst studying phishing headers on a dark terminal

Step 2 · Learn the craft

Learn to investigate phishing, coached step by step

A beginner track that walks you through the four components of every phishing email — with a coach explaining each move as you make it.

Your path

Step 1 of 4Check an email

Check an email
  1. 1Check an email

    Paste a suspicious email and read the verdict. Two minutes, no account.

  2. 2Learn the components

    See what a header, link, attachment and message body actually tell you.

  3. 3Work your first ticket

    Pick a reported email from the queue and investigate it yourself.

  4. 4Write the report

    Say what happened, what you found and what should be done about it.

The four components you'll master

Header

Received chain, SPF/DKIM/DMARC alignment, display-name vs envelope sender — and what a fail actually proves.

Content

Pretext, urgency, authority, payment or credential ask. How to describe intent instead of guessing.

Links

Defang, decompose the domain, follow the redirect chain, read a reputation verdict without over-trusting it.

Attachments

Hashes, macros, embedded objects, detonation behaviour and when a file is worth escalating.

How a coached case runs

  1. 01Read the email exactly as the reporter saw it — Outlook view or raw source.
  2. 02Flag the components you find suspicious before any tool is unlocked.
  3. 03Run the right tool for each flag; paste the result or upload the screenshot.
  4. 04Write your finding in analyst language, then get coached feedback on it.

What you walk away with

  • You can explain an authentication result out loud, not just read it.
  • You stop clicking blindly and start pivoting on evidence.
  • Every case leaves behind notes you can reuse in a real ticket.
  • You finish ready for the live queue in Investigations.

Next step

Finished the coached track? Take a live ticket.

Real SLA clock, real evidence, real containment call — and an incident report you can show an employer.

See Investigations