email-security

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Email Security & Phishing Analysis

Email Security & Phishing Analysis

ACTION REQUIRED(读完后立刻执行)

ACTION REQUIRED (Execute Immediately After Reading)

  1. NOW
    : 确认授权(分析样本邮件 / 租户配置评审)
  2. NOW
    : 不向真实用户二次投递恶意样本
  3. ACT
    : 头认证 → 内容/URL → 附件沙箱 → 租户控制面建议
  1. NOW
    : Confirm authorization (analyze sample emails / tenant configuration review)
  2. NOW
    : Do not re-deliver malicious samples to real users
  3. ACT
    : Header authentication → Content/URL → Attachment sandbox → Tenant control plane recommendations

适用场景

Applicable Scenarios

  • 钓鱼邮件拆解与 IOC
  • SPF/DKIM/DMARC 配置评估
  • BEC 商务邮件欺诈模式
  • OAuth 应用钓鱼 / 邮箱令牌滥用(联合 llm/cloud 身份)
  • 安全意识演练设计(授权)
  • Phishing email disassembly and IOC
  • SPF/DKIM/DMARC configuration evaluation
  • BEC business email fraud patterns
  • OAuth application phishing / mailbox token abuse (integrated with llm/cloud identity)
  • Security awareness drill design (authorized)

工作流

Workflow

text
□ 完整原始头:Received 链、From/Return-Path 一致性
□ SPF/DKIM/DMARC 对齐结果
□ URL 沙箱与附件静态(联合 malware-analysis)
□ 仿冒品牌与回复地址差异
□ 租户:反钓鱼策略、外部标记、MFA、OAuth app 同意
text
□ Complete original headers: Received chain, consistency between From/Return-Path
□ SPF/DKIM/DMARC alignment results
□ URL sandbox and attachment static analysis (integrated with malware-analysis)
□ Counterfeit brand and reply address discrepancies
□ Tenant: Anti-phishing policies, external tagging, MFA, OAuth app consent

工具链

Toolchain

工具用途
邮件客户端「查看源」
dig/nslookupSPF/DMARC 记录
urlscan / 沙箱链接与附件
租户管理中心策略
ToolPurpose
Email client "View Source"Headers
dig/nslookupSPF/DKIM/DMARC records
urlscan / sandboxLinks and attachments
Tenant management centerPolicies

参考

References

  • references/email-auth-checklist.md
  • ../malware-analysis/
    ../attack-chain/
    (钓鱼阶段)
    ../windows-ad/
    (令牌)
  • references/email-auth-checklist.md
  • ../malware-analysis/
    ../attack-chain/
    (Phishing phase)
    ../windows-ad/
    (Tokens)

路由上下文

Routing Context

上游: MASTER R36
MUST NOT: 未授权对第三方域群发测试钓鱼
Upstream: MASTER R36
MUST NOT: Unauthorized mass phishing testing on third-party domains

任务完成自检

Task Completion Self-Check

  • 头认证结论是否完整?
  • IOC 是否可检测化(联合 threat-hunting)?
  • Checklist?
  • Is the header authentication conclusion complete?
  • Are IOCs detectable (integrated with threat-hunting)?
  • Checklist completed?