Email Investigation Report

Working for a company that performs investigations for the government makes you more prone to receiving malicious emails. You have been personally receiving a lot of malicious emails over the last few weeks. You have decided to perform a forensic investigation into a subset of questionable emails you have received to see if there is a trend or larger attack occurring.

Complete the following steps:

  1. Select at least 10 emails to investigate. If you can safely examine them, try to include spam folder emails. For this assignment, you should consider these to be the selected questionable emails.
  2. Acquire the following information from the headers for all emails being investigating:
  3. Received headers
  4. Return path
  5. Recipients email address
  6. IP address of sending server
  7. Date and time email was sent
  8. Validate email addresses for all emails. One possible tool you can use is Email Dossier from CentralOps.net.
  9. Examine the originating IP address.
  10. Validate email header information and email origin, when possible.
  11. Determine, when possible, if email was sent from an installed email program or through web-based email.
  12. Examine email log files, if possible and if necessary.
  13. Determine if the emails are malicious and if there is a trend or larger attack occurring.
  14. Document your investigation in a 1- to 2-page report.

WRITE MY PAPER

Comments

Leave a Reply