
Explore phishing email investigation from basics to advanced, analyzing headers, URLs, and attachments. Apply static and dynamic analysis, sandboxing, and threat intel to track campaigns and report incidents to CERT.
Meet Samarjit Yadav, trainer of a cyber community with experienced members and published cyber and cloud security research. Join via YouTube, LinkedIn, Facebook, Instagram, Telegram, WhatsApp, or Udemy comments.
Learn to investigate and analyze phishing emails, categorize them as scam, legitimate, or malicious, and recognize attachments and URLs that steal sensitive information.
Explore the top five biggest phishing scams by money lost, featuring spoofed CEO emails, fake invoice scams, data leaks, and spear phishing with losses from millions to billions across companies.
Understand phishing awareness for every organization and its employees. Learn to protect financial data and online accounts from spoofed emails and cyber threats, and define standard operating procedures for compliance.
Explore common phishing techniques, including email phishing, smishing, spear phishing, and whaling, and learn to analyze phishing emails, block IOCs, and assess risky pop-up and https threats.
Vishing phishing targets you via phone calls to extract personal information and banking credentials. Stay alert to urgent requests for credentials and never reveal them.
As a SoC analyst, analyze email phishing to understand attackers' aims to steal personal information, credit card numbers, banking details, and passwords by pretending to be legitimate PayPal.
identify smishing phishing through sms, spot suspicious links like fake amazon messages, and prevent malware by not clicking links and using mobile antivirus.
Explore whaling phishing, where attackers target senior leadership such as the CEO or CTO to commit CEO fraud, often requesting payments, and learn how to investigate these attacks.
Expose pop-up phishing on legitimate websites that asks for credentials or redirects to malware, and defend systems by keeping antivirus updated and browsers current.
Explore how https phishing uses man-in-the-middle attacks to intercept data, downgrade https to http via ssl stripping, and exploit wildcard certificates to deceive users.
Spear phishing targets a single person by sending emails with malicious attachments or URLs, pretending to be a trusted sender to steal credentials or confidential data.
Inspect email headers to detect spoofing and verify sender identity using DKIM, SPF, and DMARC, and explore tools for header analysis through an Outlook demo.
Explore tools for email header analysis, paste headers into toolbox C and other analyzers, and compare Azure, Google G Suite toolbox, and Microsoft tools to identify sender details.
Explore how SPF and DKIM authenticate emails and how DMARC enforces policies like null, quarantine, or reject, using an Amazon parcel analogy to illustrate alignment and integrity.
Learn to identify spoofed emails by analyzing headers, checking the return path and SPF results, and examining the envelope sender and originating IPs to assess phishing risk.
Learn to use a sandbox for dynamic analysis of phishing emails, examining attachments, URLs, and steganography in images, and compare static analysis with open-source sandboxes like Any.run and Hybrid Analysis.
Explore open-source sandboxes for dynamic malware analysis, including any.run, hybrid analysis, and VirusTotal. Learn to submit URLs, upload attachments, review IOCs, and generate reports safely.
Analyze a phishing URL using static threat intel tools like VirusTotal and URL scan.io, then validate with dynamic analysis on any.run.
Analyze attachments via static and dynamic approaches in a VirtualBox environment, generate hashes with certutil, and assess malware via VirusTotal; then review sandbox iocs and network activity for Vidar stealer.
Conduct a full email analysis from sender domain to header, URL, and attachment to reveal spoofing, missing SPF/DKIM/DMARC, and use sandbox tools to detect ransomware indicators.
Discover how to install Sift workstation on Ubuntu via VMware or Windows Subsystem for Linux, including download, import, and login steps for digital forensics tooling and image-based phishing investigations.
Learn to investigate phishing campaigns by collecting emails, analyzing headers and payloads, identifying IOCs, monitoring infrastructure, tracking URLs, IPs, and domains, and reporting incidents with takedown steps.
Isolate a compromised machine to prevent spread. Document the incident with data, time, observations, screenshots, and logs, preserve evidence with chain of custody and metadata, and record witness statements.
Report phishing incidents to your internal cyber security team and CERT, collecting sender details and timestamps. Use built-in reporting tools, inform colleagues, and share threat intelligence to educate employees.
Develop phishing defense and prevention by prioritizing user education, advanced email filtering, and multi-factor authentication, while enabling URL inspection, TLS, DMARC/SPF, regular updates, and an incident response plan.
Follow the phishing email SOP to perform a step-by-step investigation with header, URL, and attachment analysis, assess sender domain reputation, and apply IOCs for mitigation.
Welcome to comprehnsive course of Email Analysis. This course assumes you have No prior Knowledge and by the end of the course you will able to understand the phishing concept, analyses way and to mitigate the phishing mails.
This course is divided into 9 main categories.
-->Introduction
-->Introduction to Phishing
-->Phishing Basics & Its types
-->Email Header Analysis
-->Phishing Email Analysis & Investigation
-->Advanced Investigation
-->Investigating Phishing campaign
-->Phishing Defense & Prevention
-->Phishing Email SOP
Each section of these cover the basic to Advanced level knowledge.
At the end of each section you will learn how to analyze, Mitigate and awarness yourself from the discussed videos/contents.
All the techniques in this course are practical and work against real systems, you'll understand the whole mechanism of each Phishing first, then you'll learn practical analysis and mitigation of phishing email. By the end of the course you'll be able to analyse any type of email and adopt them to suit different situations and different scenarios.
With this course you'll get 24/7 support, so if you have any questions you can post them in the Q&A section and we'll respond to you within 15 hours.
Notes: Notes:
This course is created for educational purposes only, all the analysis are launched in my own laptop and my own spam mail.
This course is totally a product of Samarjeet Yadav & Cyber Community and no other organisation is associated with it or a certification exam. Although, you will receive a Course Completion Certification from Udemy, apart from that NO OTHER ORGANISATION IS INVOLVED.