End-to-End Phishing Investigation

Phishing investigation is a controlled process that balances damage containment with evidence preservation. Document the source, time, and tools, save Hashes, build a Timeline, and separate fact, interpretation, and decision.
Incident Response and DFIR require a balance between speed, evidence preservation, business continuity, and documentation. The correct action is one that can be explained, reproduced, and reviewed after the incident. This article focuses on Phishing investigation and is intended for SOC analysts and students. The goal is to provide a methodology that can be applied in practice, during professional interviews, and in a work environment, without being limited to a dictionary definition.
The main challenge is that data is almost always incomplete. The Received chain, Return-Path, and SPF can indicate a direction, but their meaning depends on time, asset, user, and expected activity. Therefore, we will build the investigation around an investigative question, required evidence, and a clear completion criterion.
The practical scenario in the article is: A simulated Phishing scenario with a message, link, and suspicious login. All examples are laboratory data or process descriptions. When dealing with Penetration Testing, Web, or Cloud, work only with explicit permission, a defined Scope, and the ability to stop the test.




