📅 Day 54 — Investigating Phishing Through Email Gateway Logs
🎯 Goal
Today I focused on understanding email gateway logs, which are an important source of telemetry when investigating phishing incidents.
The objective was to learn:
- what investigators look for in email logs
- how malicious emails are identified
- how authentication failures reveal spoofed messages
🛠 What I Did
I explored how security teams analyze suspicious email activity.
Key investigation elements include examining:
- sender domain
- SPF results
- DKIM signatures
- DMARC alignment
- URL reputation
- attachment hashes
Email security platforms generate logs that capture these attributes for each message.
🔗 Key Cybersecurity Connections
Email gateway logs help analysts answer questions such as:
- Was the sender domain legitimate?
- Did the email pass authentication checks?
- Was the link previously associated with phishing?
- Did multiple users receive the same message?
Investigations often involve correlating multiple signals.
Example investigation flow:
Suspicious email reported
↓
Check email gateway logs
↓
Review sender domain reputation
↓
Verify SPF / DKIM / DMARC results
↓
Analyze links and attachments
🔍 Investigation Questions
If a suspicious email event appeared in security telemetry, a SOC analyst might ask:
- What domain and IP address sent the email?
- Did the message pass SPF, DKIM, and DMARC authentication checks?
- Is the sender domain newly registered or previously associated with phishing campaigns?
- Did multiple users inside the organization receive the same email?
- Did any recipients click the embedded link or download the attachment?
- Were credentials entered after visiting the linked website?
These questions help analysts determine whether the email is part of a phishing campaign or spoofing attempt.
🚨 Detection Opportunities
Possible detection strategies for phishing through email logs include:
- alerting on SPF or DKIM failures
- monitoring emails failing DMARC alignment
- detecting messages from newly registered domains
- correlating suspicious URLs with threat intelligence feeds
- flagging emails containing links to look-alike domains
Security telemetry useful for these detections includes:
- email gateway logs
- DNS logs
- web proxy logs
- endpoint browser activity.
🧭 MITRE ATT&CK Techniques
Phishing campaigns and email spoofing are associated with several MITRE ATT&CK techniques:
- T1566 – Phishing
- T1583 – Acquire Infrastructure
- T1584 – Compromise Infrastructure
- T1204 – User Execution
These techniques highlight how attackers use deceptive emails to gain initial access to systems.
⚠ Challenges
Understanding email authentication initially required learning how several systems work together.
SPF, DKIM, and DMARC interact in complex ways and can produce different results depending on:
- mail routing
- forwarding
- misconfigured domains
📚 What I Learned
Important indicators analysts look for include:
- SPF failures (sender not authorized)
- DKIM signature mismatch
- DMARC policy failures
- suspicious links or domains
- attachments with known malicious hashes
These signals can indicate phishing or spoofing attempts.
➡ Next Steps
Next topics to explore include:
- domain impersonation attacks
- typosquatting domains
- malicious infrastructure used in phishing campaigns
🧠 Reflection
Email investigation is a good example of how cybersecurity combines:
- networking knowledge
- domain reputation systems
- authentication protocols
Understanding the full pipeline is important for SOC work.
🧩 Lessons Learned
What worked
Breaking down the email delivery pipeline made the investigation process easier to understand.
What broke
At first the authentication technologies felt abstract.
Why it broke
Without seeing the investigation context, these technologies appear purely theoretical.
Fix / takeaway
Always connect protocols to real detection scenarios.
📈 Skill Progression Context
Email investigations are a core SOC skill.
This knowledge connects directly to:
- phishing detection
- incident response
- threat hunting
It also reinforces earlier learning about log analysis and telemetry interpretation.
