
Step 2 · Learn the craft
Learn to investigate phishing, coached step by step
A beginner track that walks you through the four components of every phishing email — with a coach explaining each move as you make it.
Your path
Step 1 of 4 — Check an email
- 1Check an email
Paste a suspicious email and read the verdict. Two minutes, no account.
- 2Learn the components
See what a header, link, attachment and message body actually tell you.
- 3Work your first ticket
Pick a reported email from the queue and investigate it yourself.
- 4Write the report
Say what happened, what you found and what should be done about it.
The four components you'll master
Received chain, SPF/DKIM/DMARC alignment, display-name vs envelope sender — and what a fail actually proves.
Pretext, urgency, authority, payment or credential ask. How to describe intent instead of guessing.
Defang, decompose the domain, follow the redirect chain, read a reputation verdict without over-trusting it.
Hashes, macros, embedded objects, detonation behaviour and when a file is worth escalating.
How a coached case runs
- 01Read the email exactly as the reporter saw it — Outlook view or raw source.
- 02Flag the components you find suspicious before any tool is unlocked.
- 03Run the right tool for each flag; paste the result or upload the screenshot.
- 04Write your finding in analyst language, then get coached feedback on it.
What you walk away with
- You can explain an authentication result out loud, not just read it.
- You stop clicking blindly and start pivoting on evidence.
- Every case leaves behind notes you can reuse in a real ticket.
- You finish ready for the live queue in Investigations.
Next step
Finished the coached track? Take a live ticket.
Real SLA clock, real evidence, real containment call — and an incident report you can show an employer.
See Investigations