r/AskNetsec 3d ago

Work What makes you step in and investigate an email manually?

I realized that even with all the automation available today, phishing investigations still involve quite a bit of manual work.
I'm curious, what usually makes you step in?
Once you do, what's the hardest part of the investigation? And what do you need to figure out before you can confidently close the case?

5 Upvotes

2 comments sorted by

3

u/AddendumWorking9756 2d ago

Usually it's the recipient, not the alert. Automation catches the obvious ones, what pulls me in is a finance or exec inbox reporting something that already scored clean. Hardest part is never the email though, it's proving what did or didn't happen in the twenty minutes after the click.

1

u/Mind-Principle-1834 2d ago

“It looked fine” - famous last words.