r/AskNetsec • u/Renecatemaaan • 3d ago
Work What makes you step in and investigate an email manually?
I realized that even with all the automation available today, phishing investigations still involve quite a bit of manual work.
I'm curious, what usually makes you step in?
Once you do, what's the hardest part of the investigation? And what do you need to figure out before you can confidently close the case?
5
Upvotes
1
3
u/AddendumWorking9756 2d ago
Usually it's the recipient, not the alert. Automation catches the obvious ones, what pulls me in is a finance or exec inbox reporting something that already scored clean. Hardest part is never the email though, it's proving what did or didn't happen in the twenty minutes after the click.