🎯 Goal

Today I focused on understanding email gateway logs, which are an important source of telemetry when investigating phishing incidents.

The objective was to learn:

  • what investigators look for in email logs
  • how malicious emails are identified
  • how authentication failures reveal spoofed messages

🛠 What I Did

I explored how security teams analyze suspicious email activity.

Key investigation elements include examining:

  • sender domain
  • SPF results
  • DKIM signatures
  • DMARC alignment
  • URL reputation
  • attachment hashes

Email security platforms generate logs that capture these attributes for each message.


🔗 Key Cybersecurity Connections

Email gateway logs help analysts answer questions such as:

  • Was the sender domain legitimate?
  • Did the email pass authentication checks?
  • Was the link previously associated with phishing?
  • Did multiple users receive the same message?

Investigations often involve correlating multiple signals.

Example investigation flow:

Suspicious email reported
↓
Check email gateway logs
↓
Review sender domain reputation
↓
Verify SPF / DKIM / DMARC results
↓
Analyze links and attachments


🔍 Investigation Questions

If a suspicious email event appeared in security telemetry, a SOC analyst might ask:

  • What domain and IP address sent the email?
  • Did the message pass SPF, DKIM, and DMARC authentication checks?
  • Is the sender domain newly registered or previously associated with phishing campaigns?
  • Did multiple users inside the organization receive the same email?
  • Did any recipients click the embedded link or download the attachment?
  • Were credentials entered after visiting the linked website?

These questions help analysts determine whether the email is part of a phishing campaign or spoofing attempt.


🚨 Detection Opportunities

Possible detection strategies for phishing through email logs include:

  • alerting on SPF or DKIM failures
  • monitoring emails failing DMARC alignment
  • detecting messages from newly registered domains
  • correlating suspicious URLs with threat intelligence feeds
  • flagging emails containing links to look-alike domains

Security telemetry useful for these detections includes:

  • email gateway logs
  • DNS logs
  • web proxy logs
  • endpoint browser activity.

🧭 MITRE ATT&CK Techniques

Phishing campaigns and email spoofing are associated with several MITRE ATT&CK techniques:

  • T1566 – Phishing
  • T1583 – Acquire Infrastructure
  • T1584 – Compromise Infrastructure
  • T1204 – User Execution

These techniques highlight how attackers use deceptive emails to gain initial access to systems.


⚠ Challenges

Understanding email authentication initially required learning how several systems work together.

SPF, DKIM, and DMARC interact in complex ways and can produce different results depending on:

  • mail routing
  • forwarding
  • misconfigured domains

📚 What I Learned

Important indicators analysts look for include:

  • SPF failures (sender not authorized)
  • DKIM signature mismatch
  • DMARC policy failures
  • suspicious links or domains
  • attachments with known malicious hashes

These signals can indicate phishing or spoofing attempts.


➡ Next Steps

Next topics to explore include:

  • domain impersonation attacks
  • typosquatting domains
  • malicious infrastructure used in phishing campaigns

🧠 Reflection

Email investigation is a good example of how cybersecurity combines:

  • networking knowledge
  • domain reputation systems
  • authentication protocols

Understanding the full pipeline is important for SOC work.


🧩 Lessons Learned

What worked

Breaking down the email delivery pipeline made the investigation process easier to understand.

What broke

At first the authentication technologies felt abstract.

Why it broke

Without seeing the investigation context, these technologies appear purely theoretical.

Fix / takeaway

Always connect protocols to real detection scenarios.


📈 Skill Progression Context

Email investigations are a core SOC skill.

This knowledge connects directly to:

  • phishing detection
  • incident response
  • threat hunting

It also reinforces earlier learning about log analysis and telemetry interpretation.