Reader small image

You're reading from  Effective Threat Investigation for SOC Analysts

Product typeBook
Published inAug 2023
PublisherPackt
ISBN-139781837634781
Edition1st Edition
Right arrow
Author (1)
Mostafa Yahia
Mostafa Yahia
author image
Mostafa Yahia

Mostafa Yahia is a skilled and motivated threat investigator and hunter with a wealth of experience investigating and hunting down various cyber threats. He is a proven leader in building and leading cybersecurity-managed services such as SOC and threat-hunting services. Mostafa holds a bachelor's degree in computer science, which he earned in 2016, and has furthered his education by earning multiple industry-recognized certifications, including GCFA, GCIH, CCNA, and IBM QRadar. In addition to his professional work, Mostafa also shares his knowledge through free courses and lessons on his YouTube channel. Currently, he serves as the senior lead for cyber defence services in an MSSP company, overseeing SOC, TH, DFIR, and CA services.
Read more about Mostafa Yahia

Right arrow

Email Flow and Header Analysis

Due to the increase in email threats and the use of spoofing techniques to impersonate known legitimate domains, it has become crucial for SOC analysts to understand the email message flow and email authentication process, as well as analyze email headers to collect additional artifacts and investigate and observe potential spoofing attempts.

The objective of this chapter is to learn about the email message flow and understand email authentication protocols such as Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-Based Message Authentication, Reporting, and Conformance (DMARC) and how they work. You will also learn how to analyze an email’s message header and observe any spoofing attempts by analyzing it.

In this chapter, we’re going to cover the following main topics:

  • Email flow
  • Email header analysis
  • Email authentication
  • Investigating the email header of a spoofed message

Let...

Email flow

An email flow is the flow path that an email follows and the hops that the email passes when sent from the sender until it's delivered to the recipient. The email crosses multiple hops between the sender and the recipient before it is delivered. Most of them use SMTP. Let’s take a look at these hops in detail:

  • Mail User Agent (MUA): This refers to the agent is used by the client to send the email. Examples include Outlook and browsers such as Google Chrome, Mozilla Firefox, and others.
  • Mail Submission Agent (MSA): The server that receives the email after the client has submitted it from its MUA.
  • Mail Transfer Agent (MTA): Also known as the SMTP relay server, this is the email server that receives the message from the MSA and passes it to several MTA servers until it’s delivered to the recipient’s mail exchange server.
  • Mail Exchange (MX): The email server that is responsible for receiving messages intended for a particular domain...

Email header analysis

Email header analysis is the process of analyzing every aspect of the email header to identify the email sender, sender IP, passed hops, email subject, email recipient, email timestamps, and email authentication results. Additionally, to be able to identify the presence of email spoofing.

In this section, we will analyze the email header of a legit email message sent from mia7ia@yahoo.com to mostafayahia753@gmail.com to investigate the email header and collect possible digital evidence. You can implement several methods to acquire the email message header, depending on the email application you use. For example, if you use the Microsoft Outlook app, you need to click File. Then, from Info, you must select Properties. Alternatively, if you’re using the Gmail web application, you must click More and then choose Show original. Additionally, it may be possible to obtain the header from your email secure gateway appliance, if available.

In this case, I...

Investigating the email header of a spoofed message

In the previous section, we analyzed the email header of a legitimate and non-spoofed email message, and we learned about the various email authentication protocols, how they work, and the expected results of a successful email authentication process. In this section, we will examine the email authentication result of a spoofed email message to understand what it looks like when email authentication fails.

In this section, we will thoroughly examine the email authentication results of an email purporting to be sent from the fedex.com domain to the mostafayahia753@gmail.com email address. To investigate the email message, we followed the steps outlined in Chapter 1, which led us to conclude that the email was indeed malicious and contained a harmful attachment designed to gain unauthorized access to the victim’s machine. Our investigation raised the possibility that an attacker may have compromised one of the fedex.com users...

Summary

In this chapter, we covered the email message flow and the hops that the email traverses until it’s delivered to the recipient. We also learned about email authentication records and protocols, how they work, and how to investigate the authentication results using the email header. Finally, we learned how to analyze the email message header before investigating the email header of a spoofed email message.

In the next chapter, we will enter a new section of this book and introduce various Windows event log types.

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Effective Threat Investigation for SOC Analysts
Published in: Aug 2023Publisher: PacktISBN-13: 9781837634781
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €14.99/month. Cancel anytime

Author (1)

author image
Mostafa Yahia

Mostafa Yahia is a skilled and motivated threat investigator and hunter with a wealth of experience investigating and hunting down various cyber threats. He is a proven leader in building and leading cybersecurity-managed services such as SOC and threat-hunting services. Mostafa holds a bachelor's degree in computer science, which he earned in 2016, and has furthered his education by earning multiple industry-recognized certifications, including GCFA, GCIH, CCNA, and IBM QRadar. In addition to his professional work, Mostafa also shares his knowledge through free courses and lessons on his YouTube channel. Currently, he serves as the senior lead for cyber defence services in an MSSP company, overseeing SOC, TH, DFIR, and CA services.
Read more about Mostafa Yahia