I7.8 Email Security and Phishing Defense Lab
Combine sender analysis, authentication, social engineering, links, attachments, business email compromise, filtering, logs, user reports, account evidence, business systems, containment, validation, monitoring, and closure into one portfolio-ready fictional investigation.
Lesson Progress
Email Security and Phishing Defense Lab
High School Intermediate • I7: Email Security and Phishing Defense • Lesson 8 of 8
Readiness Check
Before You Start
0/5 ready
Professional Hook
The Best Investigation Does More Than Identify a Phishing Message
A professional defender must explain who received the fictional message, which sender identity authenticated, how the message tried to influence users, where its link and attachment led, which users interacted, whether accounts or devices changed, whether payroll or benefits records changed, what controls acted, what remains unknown, and what evidence is required for closure.
Weak case summary
“The email was phishing, one user clicked, and the incident is resolved.”
Strong case summary
“The message and content are confirmed phishing, recipient actions differ, account compromise is not confirmed for B, device impact remains unknown for C, and closure depends on validation and accepted residual risk.”
Objective 1
Integrate fictional sender identity, domain analysis, authentication, social-engineering review, link and attachment evidence, business-process verification, filtering decisions, logs, and user reports into one defensible case.
Objective 2
Build a normalized fictional timeline that separates message creation, transport, filtering, delivery, mailbox activity, link or attachment interaction, account activity, transaction activity, containment, recovery, validation, and closure.
Objective 3
Distinguish confirmed facts, reasonable conclusions, alternative explanations, confidence, evidence gaps, and unsupported claims.
Objective 4
Create findings with owners, priorities, remediation, validation, monitoring, rollback, and residual-risk documentation.
Objective 5
Produce a portfolio-ready fictional Email Security and Phishing Defense Case Report that demonstrates professional investigation and decision-making.
Case Profile
Fictional Meadowbrook Phishing Investigation
Organization
Fictional Meadowbrook Learning Network
A training-only school and services environment with finance, human resources, technology, teachers, vendors, students, and shared mailboxes.
Initial report
Urgent benefits and payroll message
A fictional employee reports a message that claims an account review is required before the next payroll cycle.
Claimed sender
Meadowbrook Benefits Support
The display name resembles an internal function, but the visible sender uses an unfamiliar external domain.
Requested action
Open a document, sign in, and confirm payroll details
The message combines a cloud-share link, an HTML attachment, urgency, authority, and a sensitive-data request.
Known business process
Trusted payroll portal and HR ticketing system
Real changes require the known portal, employee identity verification, an HR case, and owner approval.
Investigation challenge
Mixed user and account evidence
One recipient reports without interaction, one confirms a click, and one has an attachment-download record with incomplete device evidence.
Evidence Sources
Eight Sources Required for the Lab
Original message and headers
Records
Fictional display name, visible address, Reply-To, envelope sender, return path, message ID, subject, recipients, body, attachment name, link text, and authentication results.
Investigation question
Which sender identities and message elements are directly confirmed?
Limitation
Headers and content do not prove physical sender identity, user interaction, or downstream impact.
Message trace and gateway
Records
Fictional route, sending infrastructure, timestamps, recipients, SPF, DKIM, DMARC, risk score, warning, quarantine, delivery, and post-delivery actions.
Investigation question
Who received the message, which controls acted, and what was the final delivery state?
Limitation
Delivery and filtering records do not automatically prove that recipients viewed or used the content.
URL and redirect evidence
Records
Fictional visible link text, encoded address, redirect chain, final parent domain, page classification, click records, warning, and block state.
Investigation question
Which destination is confirmed, and which recipients are confirmed to have visited it?
Limitation
A click does not prove credential entry, MFA approval, or account compromise.
Attachment evidence
Records
Fictional file name, extension, MIME type, detected structure, forms, external references, verdict, delivery, download, open state, and authorized analysis.
Investigation question
What content was delivered, downloaded, or opened, and what does the file evidence support?
Limitation
Attachment presence, download, open, active-content use, and execution are different stages.
Mailbox and user evidence
Records
Fictional read state, folder move, reply, forward, report-phishing event, user statement, preview behavior, and shared-mailbox context.
Investigation question
How did each recipient handle the message, and where do technical and human evidence agree or conflict?
Limitation
Read state and user memory can be affected by client behavior, synchronization, and incomplete recall.
Identity and session evidence
Records
Fictional sign-ins, failures, MFA, factor changes, recovery, sessions, devices, mailbox rules, forwarding, password reset, and application activity.
Investigation question
Is any account activity connected to the message by user, time, device, session, and destination evidence?
Limitation
Nearby account activity may have another cause and should not be treated as proof without correlation.
Business-system evidence
Records
Fictional payroll portal, HR ticket, employee record, vendor record, payment state, data-sharing history, approvals, owners, and system-of-record status.
Investigation question
Did any payroll, benefits, payment, data, permission, or account state actually change?
Limitation
A business record shows system state but may not identify the person behind the request.
Containment and validation evidence
Records
Fictional quarantine, destination block, file block, session revocation, credential recovery, user communication, positive tests, negative tests, monitoring, and closure approvals.
Investigation question
Which actions succeeded, what legitimate communication remains available, and what risk remains?
Limitation
An action request is not proof of successful completion until validated.
Integrated Lab Workflow
Eight Phases from Scope to Portfolio
Scope the case
Goal
Define the fictional sender, recipients, message, time range, business request, systems, initial reports, and investigation questions.
Deliverable
A one-page case scope with known facts, immediate risks, evidence sources, owners, and safety boundaries.
Quality checkpoint
Can another reviewer explain exactly what is being investigated and what is outside scope?
Preserve and normalize
Goal
Collect the fictional message, headers, trace, gateway, URL, attachment, mailbox, identity, user, business, and response evidence.
Deliverable
An evidence register with source, identifier, timestamp, time zone, owner, retention, reliability, and limitation.
Quality checkpoint
Are timestamps normalized and correlation identifiers preserved before conclusions are written?
Analyze sender and request
Goal
Compare fictional display name, addresses, domain, Reply-To, SPF, DKIM, DMARC, alignment, relationship, social engineering, and business process.
Deliverable
A sender-and-request worksheet that identifies exact mismatches, expected exceptions, and independent verification.
Quality checkpoint
Does the analysis explain which domain authenticated without treating authentication as complete legitimacy?
Analyze links and attachments
Goal
Map fictional visible text, encoded and final destinations, redirects, page purpose, file metadata, structure, verdicts, and safe handling.
Deliverable
A content map that separates presence, delivery, click, download, open, form use, and confirmed impact.
Quality checkpoint
Are suspicious content conclusions based on supplied evidence rather than opening or interacting with the content?
Build the timeline
Goal
Order fictional creation, delivery, filtering, user, URL, attachment, identity, business, containment, recovery, validation, and monitoring events.
Deliverable
A normalized timeline with evidence citations, event meaning, alternative explanations, and confidence.
Quality checkpoint
Does the timeline avoid turning temporal proximity into unsupported causation?
Write findings
Goal
Create separate fictional message, interaction, account, device, business, control, and response findings.
Deliverable
Findings with facts, conclusions, impact, confidence, owner, priority, remediation, and validation.
Quality checkpoint
Can every conclusion be traced to specific evidence and an explicit limitation?
Contain, recover, and validate
Goal
Recommend narrow fictional quarantine, blocking, transaction holds, account recovery, user communication, control tuning, positive tests, and negative tests.
Deliverable
A response plan with owners, sequence, dependencies, rollback, success criteria, and residual risk.
Quality checkpoint
Does the plan protect legitimate communication while addressing the confirmed risk?
Close and present
Goal
Summarize fictional scope, evidence, timeline, findings, actions, gaps, monitoring, owner acceptance, and closure decision.
Deliverable
A portfolio-ready case report and one-page executive summary.
Quality checkpoint
Would a technical reviewer and business owner reach the same understanding from the report?
Core Investigation Model
Separate Six Questions Before Writing the Final Story
Sender
Which fictional identity, domain, account, service, and business role created the message?
Content
What did the fictional message, link, attachment, and social-engineering request contain?
Delivery
Which fictional recipients, folders, warnings, quarantines, and post-delivery actions are confirmed?
Interaction
Which fictional users viewed, reported, clicked, downloaded, opened, entered information, or replied?
Impact
Which fictional account, device, payroll, benefits, data, permission, or transaction state changed?
Response
Which fictional containment, recovery, validation, monitoring, owner, and closure actions succeeded?
Supplied Evidence
Twenty-Two Fictional Records for Correlation
E-01
08:41:02
Message
Display name is “Meadowbrook Benefits Support,” visible From is review@meadowbrook-benefits.example, and Reply-To is help@benefits-confirm.example.
The message presents two external sender identities while claiming an internal support role.
E-02
08:41:05
Authentication
SPF passes for mailer.meadowbrook-benefits.example, DKIM passes for meadowbrook-benefits.example, and DMARC passes through aligned DKIM.
The external domain authenticates its own message correctly.
E-03
08:41:08
Gateway
The fictional message receives medium risk for a newly observed domain, payroll language, an HTML attachment, and a shortened link.
The tool identifies several contextual concerns but does not block the message initially.
E-04
08:41:11
Delivery
The message is delivered to six fictional recipients with an external-sender warning banner.
Recipient scope and initial delivery are confirmed.
E-05
08:43:17
Recipient A
Mailbox records show message open and report-phishing events with no URL, attachment, reply, or forward event.
Recipient A viewed and reported the message without confirmed content interaction.
E-06
08:44:26
Recipient B
URL protection records a click on the rewritten document link from a managed browser.
Recipient B is confirmed to have visited the linked destination.
E-07
08:44:28
Redirect
The fictional link moves through a shortener and ends at payroll-review.example/login.
The final parent domain is unrelated to the approved payroll portal.
E-08
08:44:30
Destination
The fictional page imitates a payroll sign-in and requests email, password, and MFA code.
The supplied destination evidence supports a credential-phishing purpose.
E-09
08:45:04
Recipient C
Attachment telemetry shows Benefits_Review.html was downloaded, while open-state evidence is unavailable because the fictional device stopped reporting.
Download is confirmed, but open, form use, or execution remains unknown.
E-10
08:46:10
File analysis
Authorized fictional analysis identifies an HTML form and an external reference to payroll-review.example.
The attachment is connected to the same deceptive destination pattern.
E-11
08:47:00
User interview B
Recipient B states that the page opened but no credentials or MFA code were entered.
The user statement supports no information entry but requires technical correlation.
E-12
08:47:42
Browser B
The fictional managed browser records destination load and page close with no form-submission event.
Browser evidence supports a visit without confirmed form submission.
E-13
08:48:13
Identity B
One failed sign-in from an unfamiliar browser occurs, followed by no successful new session, factor change, recovery, or password reset.
The account evidence raises a question but does not confirm compromise.
E-14
08:49:00
Human Resources
The fictional HR owner confirms no benefits or payroll review was scheduled and no ticket exists.
The request is not part of the approved business process.
E-15
08:50:20
Payroll system
No fictional employee profile, direct-deposit, tax, benefits, or payroll account change is recorded for any recipient.
No confirmed payroll-system impact appears in the reviewed scope.
E-16
08:52:00
Reclassification
The URL and attachment verdicts change from unknown to suspicious, and later access is blocked.
New evidence creates a post-delivery control action.
E-17
08:54:00
Related-message search
Fourteen fictional related messages share the sender domain, subject pattern, link, and attachment.
Campaign scope is larger than the first six recipients.
E-18
08:57:00
Containment
The fourteen related messages are quarantined and the narrow destination and attachment patterns are blocked.
Message and content containment are recorded.
E-19
09:03:00
Identity review
No fictional persistent sessions, factor changes, recovery events, mailbox rules, forwarding changes, or suspicious application access are found for Recipients A or B.
The reviewed identity evidence does not confirm account compromise for A or B.
E-20
09:06:00
Device gap C
Recipient C’s fictional device telemetry is unavailable after the attachment download because the device is offline.
Attachment-open and device-impact questions remain unresolved.
E-21
09:12:00
User communication
Affected fictional recipients receive a factual notice with reporting, trusted-portal, account-review, and support instructions.
User communication supports coordinated containment and verification.
E-22
Day 2
Validation
Legitimate payroll messages and the trusted portal remain available, the deceptive patterns remain blocked, and no new related account or payroll activity appears.
Short-term technical and business validation is complete, while Recipient C’s device gap remains open.
Professional Findings
Eight Findings with Separate Impact and Ownership
External benefits identity impersonates an internal function
Fact
The fictional message uses an unfamiliar external From domain and a separate external Reply-To while claiming to be Meadowbrook Benefits Support.
Conclusion
The sender identity is inconsistent with the approved internal HR and payroll communication path.
Impact
Six initial recipients and fourteen total related messages were exposed to the impersonation attempt.
Owner
Email Security and Human Resources
Authentication pass does not validate the claimed organization
Fact
The fictional external domain passes SPF, DKIM, and DMARC for itself.
Conclusion
Authentication confirms domain authorization but not the claimed internal identity or business request.
Impact
The message could appear technically valid to users or controls that rely too heavily on pass results.
Owner
Email Security Architecture
Link and attachment lead to the same deceptive credential workflow
Fact
The fictional shortened link and HTML attachment both reference payroll-review.example and present payroll-style credential collection.
Conclusion
The supplied link and attachment evidence supports a coordinated credential-phishing delivery pattern.
Impact
One confirmed click and one confirmed attachment download require recipient-specific investigation.
Owner
Email Security Operations
Recipient A safely reported without confirmed content interaction
Fact
Mailbox, URL, attachment, and user records agree that Recipient A opened and reported the message without clicking, downloading, replying, or forwarding.
Conclusion
Recipient A followed the approved reporting process and requires no evidence-based account recovery action.
Impact
The report helped trigger campaign review and later containment.
Owner
Security Awareness and Case Investigator
Recipient B clicked, but account compromise is not confirmed
Fact
A fictional URL click and browser visit are confirmed, while no form submission, persistent new session, factor change, recovery, or application change is found.
Conclusion
Recipient B interacted with the phishing destination, but the available evidence does not establish credential entry or account compromise.
Impact
Monitoring and risk-based identity review remain appropriate because one nearby failed sign-in is unresolved.
Owner
Identity Operations and Case Investigator
Recipient C has an unresolved device-evidence gap
Fact
The fictional attachment download is recorded, but device telemetry becomes unavailable before open or execution state can be determined.
Conclusion
The investigation cannot confirm or exclude later attachment interaction or device impact.
Impact
The case cannot fully close for Recipient C without restored evidence, approved device review, or accepted residual risk.
Owner
Endpoint Operations and Case Owner
No payroll or benefits-system change is confirmed
Fact
The fictional systems of record show no profile, direct-deposit, tax, benefits, or payroll account change for any recipient.
Conclusion
No confirmed business-system impact appears in the reviewed time range.
Impact
The incident remains an attempted phishing campaign with recipient interaction but no confirmed payroll diversion.
Owner
Payroll Owner and Human Resources
Post-delivery reclassification contained the wider campaign
Fact
Fourteen fictional related messages were quarantined after URL and attachment verdicts changed, and narrow destination and file patterns were blocked.
Conclusion
Post-delivery controls reduced further exposure after initial delivery.
Impact
The organization still needs to review interaction that occurred before containment and improve earlier contextual detection.
Owner
Email Security Operations and Detection Engineering
Remediation Plan
Eight Coordinated Actions with Validation and Rollback
Preserve the full fictional case record
Maintain original message, headers, trace, URL, attachment, mailbox, identity, user, business, containment, and validation evidence.
Owner
Case Investigator
Validation
Confirm every cited finding maps to an evidence identifier, timestamp, source, and limitation.
Rollback or reopening
Not applicable; preservation should remain read-only and access controlled.
Maintain narrow message and content containment
Prevent additional access to the fictional sender, destination, and attachment patterns while avoiding broad platform blocking.
Owner
Email Security Operations
Validation
Confirm all fourteen related messages are quarantined and later access to the deceptive patterns is blocked.
Rollback or reopening
Remove only after verified false-positive evidence and accountable owner approval.
Complete Recipient B identity monitoring
Address the confirmed click and nearby failed sign-in without overstating account compromise.
Owner
Identity Operations
Validation
Review sessions, factors, recovery, password events, applications, mailbox rules, and delayed activity for the defined monitoring period.
Rollback or reopening
End enhanced monitoring after the approved period if no related activity appears.
Resolve Recipient C device evidence
Determine whether the downloaded fictional HTML attachment was opened or produced any device activity.
Owner
Endpoint Operations
Validation
Restore telemetry or complete an approved device review and document open, browser, process, file, and persistence evidence.
Rollback or reopening
Return the device to normal monitoring only after the owner accepts the evidence and residual risk.
Validate payroll and HR systems
Confirm the fictional phishing request did not change employee, payroll, benefits, tax, direct-deposit, or account records.
Owner
Payroll and Human Resources
Validation
Compare systems of record, owner approvals, pending requests, and recent changes for all affected recipients.
Rollback or reopening
Reverse any unauthorized change through the approved business process if later discovered.
Improve contextual detection
Combine fictional internal-function impersonation, new external domain, payroll language, shortened link, HTML attachment, and sensitive request evidence.
Owner
Detection Engineering
Validation
Test the original campaign pattern, legitimate payroll notices, approved vendors, and unrelated external messages.
Rollback or reopening
Restore the previous rule if legitimate communication is disrupted and document the failed condition.
Reinforce independent verification
Give fictional users a trusted route for payroll, benefits, account, and document requests without using message-controlled links or attachments.
Owner
Security Awareness, HR, and Payroll
Validation
Confirm users can locate the known portal, HR ticketing path, and report-phishing function in a training exercise.
Rollback or reopening
Revise communication if testing shows confusion or inaccessible instructions.
Close with accountable residual-risk acceptance
Ensure unresolved evidence, especially Recipient C’s device gap, is visible and owned rather than hidden.
Owner
Incident Owner and Business Owners
Validation
Confirm technical and business closure criteria, open tasks, monitoring duration, accepted uncertainty, and final approvals.
Rollback or reopening
Reopen the case if new related message, identity, device, or payroll evidence appears.
Closure Gate
Ten Requirements Before Final Approval
All fictional related messages, recipients, sender identities, URLs, attachments, and delivery states are documented.
Each recipient is classified separately for view, report, reply, click, download, open, information entry, account activity, and business impact.
All confirmed high-risk content is contained through narrow, approved controls.
Recipient B’s identity review and monitoring period are complete or formally handed off with an owner and due date.
Recipient C’s device gap is resolved or accepted by an accountable owner with documented residual risk and monitoring.
Payroll and Human Resources confirm no unauthorized employee, benefits, tax, direct-deposit, or payroll change.
Legitimate payroll, benefits, collaboration, and support communication remains available through approved paths.
Positive and negative validation tests demonstrate that tuned controls restore business use without weakening confirmed protections.
Evidence gaps, alternative explanations, confidence, monitoring duration, rollback criteria, and case-reopening triggers are documented.
Technical and business owners approve the final report and closure decision.
Fake Dashboard
Fake Integrated Email Defense Case Dashboard
Training dashboard for the fictional Meadowbrook Learning Network investigation.
Related messages
14
Fictional messages share the external sender domain, subject pattern, shortened link, and HTML attachment.
Recipient outcomes
3
Safe report without interaction, confirmed click without confirmed compromise, and confirmed download with unresolved device evidence.
Open evidence gaps
1
Recipient C’s fictional device telemetry remains unavailable after attachment download.
Fake SOC Alert
Integrated Phishing Case Requires Recipient-Specific Conclusions
Source: Fake Meadowbrook Email Defense Console • Time: 08:44 AM
Fake Log Panel
Fake Integrated Case Timeline
08:41:02 MESSAGE from='review@meadowbrook-benefits.example' reply_to='help@benefits-confirm.example' 08:41:05 AUTH spf='pass' dkim='pass' dmarc='pass_for_external_domain' 08:41:08 GATEWAY risk='medium' signals='new_domain,payroll,html,short_link' 08:41:11 DELIVERY recipients='6' warning='external_sender' 08:43:17 RECIPIENT_A opened='true' reported='true' content_interaction='none' 08:44:26 RECIPIENT_B url_click='confirmed' 08:44:28 REDIRECT final_domain='payroll-review.example' 08:44:30 PAGE purpose='credential_collection' 08:45:04 RECIPIENT_C attachment_download='confirmed' later_telemetry='unavailable' 08:46:10 FILE attachment='Benefits_Review.html' external_reference='payroll-review.example' 08:47:42 BROWSER_B form_submission='none' 08:48:13 IDENTITY_B failed_new_browser='1' persistent_session='0' 08:49:00 HR_VERIFY request='not_authorized' ticket='none' 08:50:20 PAYROLL changes='0' 08:52:00 RECLASSIFY url='suspicious' attachment='suspicious' 08:54:00 SEARCH related_messages='14' 08:57:00 CONTAIN quarantine='14' narrow_blocks='active' 09:03:00 IDENTITY_REVIEW A_compromise='not_confirmed' B_compromise='not_confirmed' 09:06:00 EVIDENCE_GAP recipient='C' device_state='unknown' DAY2 VALIDATION legitimate_payroll='working' new_related_activity='0'
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
Which Integrated Case Conclusion Is Best Supported?
Which final conclusion is strongest?
Common Mistakes
Mistakes That Lower the Quality of the Final Report
Final Lab Assignment
Produce the Meadowbrook Email Defense Case Report
Required Sections
- Executive summary and fictional case scope.
- Safety boundary and evidence-preservation statement.
- Sender, domain, authentication, and social-engineering analysis.
- Link, redirect, destination, attachment, and file analysis.
- Normalized message, user, identity, device, business, and response timeline.
- Recipient-specific interaction and impact classifications.
- Findings with facts, conclusions, confidence, priority, impact, and owners.
- Containment, remediation, validation, rollback, monitoring, and reopening plan.
- Evidence gaps, alternatives, residual risk, closure criteria, and owner approval.
Quality Standard
- Every conclusion cites supplied fictional evidence.
- Authentication is interpreted accurately and narrowly.
- Each recipient receives a separate interaction and impact conclusion.
- Facts, inferences, alternatives, confidence, and gaps are visibly separated.
- Actions have owners, order, success criteria, validation, and rollback.
- Legitimate business communication is tested and preserved.
- Unresolved evidence is owned rather than hidden.
- The final report is understandable to technical and business reviewers.
Scenario Decision Lab
Recipient B Clicked, but Account Evidence Is Incomplete
A fictional recipient visits the deceptive payroll page. Browser evidence shows no form submission, but one failed sign-in from a new browser occurs shortly afterward. No persistent session, factor change, recovery, password reset, or payroll change is found.
Scenario Decision Lab
Recipient C Downloaded the Attachment, but the Device Is Offline
A fictional attachment download is confirmed, but device telemetry becomes unavailable before investigators can determine whether the HTML file was opened or used.
Defender Habits
Email Security and Phishing Defense Lab Checklist
Check Your Understanding
I7.8 Mini Quiz: Email Security and Phishing Defense Lab
Choose your answers first. Explanations appear only after submission.
1. What is the strongest conclusion about the fictional external domain when SPF, DKIM, and DMARC pass?
2. Recipient B has a confirmed click but no form submission or persistent new session. What is the strongest conclusion?
3. How should Recipient C’s fictional attachment evidence be classified?
4. Which response best protects the business while investigating a sensitive payroll request?
5. What is the strongest way to validate a detection change?
6. Why should each fictional recipient receive a separate interaction classification?
7. Which closure decision is strongest while Recipient C’s device evidence remains unavailable?
Portfolio Prompt
Portfolio Prompt
Produce the complete fictional Meadowbrook Email Security and Phishing Defense Case Report using the supplied evidence. Include an executive summary, scope, evidence register, sender and authentication analysis, social-engineering analysis, link and attachment maps, normalized timeline, recipient-specific classifications, account and device review, business-impact review, findings, remediation, validation, monitoring, rollback, evidence gaps, residual risk, closure criteria, and owner approvals.
Key Takeaways
What You Should Remember
Navigation