Festival Season Offer15% off on all our programmes — claim it before you enrol
← All Career InsightsSOC Analyst

How does a SOC analyst investigate a phishing email?

A SOC analyst investigates a reported phishing email by preserving the original message, reading its headers to see where it really came from, checking its links and attachments safely, and then finding everyone else who received or clicked it. The analyst contains the threat, for example by blocking the sender and resetting exposed passwords, and records each step for the incident report.

Why phishing is a daily SOC task

Phishing is one of the most common ways attackers get a first foothold, so reported suspicious emails reach most SOC teams every day. Each report needs a quick, consistent answer: is this malicious, who else is affected, and has anyone already acted on it.

The goal is not only to judge one message. It is to scope the whole campaign, because the same email usually lands in many inboxes at once.

A phishing investigation step by step

Follow your organisation's playbook where one exists; this is the common shape of the work.

  1. Preserve the original email

    Get the message as an attachment or .eml file with full headers. A forwarded copy loses the evidence you need. Ask the reporter not to click anything further.

  2. Read the headers

    Compare the visible From address with the Return-Path and Reply-To. Check the Authentication-Results line for SPF, DKIM and DMARC outcomes, and trace the Received lines to the sending server.

  3. Check the links safely

    Copy URLs without clicking, and defang them in your notes (for example hxxp and example[.]com). Look up the domains in threat intelligence sources and open them only inside an approved sandbox.

  4. Check attachments safely

    Calculate the file hash and search for it in threat intelligence. Detonate the file only in an approved sandbox, and follow policy before uploading anything to a public service, because files can contain company data.

  5. Scope the campaign

    Search mail logs for the same sender, subject, link or attachment hash to find every recipient. Check proxy and endpoint logs or the SIEM for anyone who opened the link or ran the file.

  6. Contain and remediate

    Remove the email from all inboxes, block the sender and malicious domains, and reset passwords or revoke sessions for anyone who entered credentials. Isolate any machine that ran a malicious file.

  7. Document and escalate

    Record the indicators, affected users, actions taken and times. Escalate to L2 or incident response if anyone was compromised, then reply to the person who reported it.

Signs that point to phishing

No single sign proves it, but several together should raise suspicion:

  • A display name that looks familiar with an unrelated sending address.
  • SPF, DKIM or DMARC failures for a domain that normally passes.
  • Links whose real destination differs from the visible text, or lookalike domains.
  • Urgent requests to log in, pay, reset a password or open an attachment.
  • Unexpected attachments, especially archives, macros or HTML files.
  • A newly registered domain or one with no history in your mail logs.

Quick answers about phishing investigation

Short answers to what SOC learners ask most.

What is the first thing to do when a phishing email is reported?

Preserve the original message with full headers, usually as an .eml file or attachment, and tell the reporter not to click or forward it further. Everything else depends on that evidence.

How can I tell if an email is spoofed?

Read the headers. A mismatch between the From, Return-Path and Reply-To addresses, together with SPF, DKIM or DMARC failures, strongly suggests the sender is not who they claim to be.

Should a SOC analyst click the link in a phishing email?

Not on a normal machine. Copy the URL without clicking, check it with threat intelligence, and open it only inside an approved sandbox or isolated analysis environment.

What happens if a user already entered their password?

Treat the account as compromised: reset the password, revoke active sessions, check sign-in logs for unusual access, and escalate according to the incident response process.

Which tools help with phishing analysis?

The mail platform's message trace and search, a SIEM for related log activity, threat intelligence lookups for domains and hashes, and a sandbox for links and files are the usual set.

More SOC guides to read next

See how investigations like this are taught in the SOC Analyst programme, or read the related guides.

See the SOC Analyst programmeRead: incident response step by stepRead: writing a clear incident handoffRead: what a SIEM is and which to learnRead: tools SOC Analysts useBrowse all Career Insights

Evidence first, then scope, then contain

Keep the original message, read what the headers really say, check links and files only in safe places, and find every recipient before you close the ticket. A consistent routine makes each phishing report faster than the last.

Train for a SOC Analyst role

The same programme, duration and fees, with the learning path built around one job role.

SOC AnalystIncident Response AnalystThreat HunterSIEM EngineerSecurity Monitoring AnalystThreat Intelligence Analyst

Practise SOC investigations hands-on

Ask our team how the SOC Analyst programme trains alert and phishing analysis.

Our admissions team will call you back within 90 minutes.
AddressLR Towers, No. 3-535, 3rd Floor A Section, 100 Feet Road, Ayappa Society, Madhapur, Hyderabad, Telangana, India