Hmm, I'm not sure about F. Wouldn't that just be internal information for the security team? I'd focus on the external indicators that could help identify the phishing source.
Ha! I bet the security team would also want to know the 'state of the phishing email' - you know, like if it was opened, clicked, or forwarded. That's a good one, C!
A, D, and E for sure. I mean, that's the basic info you'd want to capture, right? The URLs, IPs, and file hashes could be clues to the source of the phishing attack.
Art
8 months agoLorrine
8 months agoYolande
7 months agoAmber
7 months agoCarissa
7 months agoLucia
8 months agoDevora
8 months agoJamika
8 months agoBrittney
7 months agoErick
8 months agoWilda
8 months agoLatanya
8 months agoAnastacia
9 months agoSolange
8 months agoLigia
8 months agoLeontine
8 months ago