-
Book Overview & Buying
-
Table Of Contents
-
Feedback & Rating

Effective Threat Investigation for SOC Analysts
By :

Email gateway security is a security solution that checks and analyzes every email, including its content, sent from external email addresses to internal email addresses and vice versa. Such an inline position allows email security controls to have visibility of all emails sent and received, which makes its logs very valuable during threat detection and investigations.
Email security solutions typically provide several types of logs to help organizations monitor and analyze email activity. Here are some common types of logs:
During this section, we will discuss and analyze the most common log fields that are generated and exist in all security email gateways, regardless of product name or vendor:
Purchase order
, Important note
, and Invoice
) will help you detect the spearphishing attachment emails.Now that we are familiar with the most common possible log fields in all email security gateway logs, let us learn how to investigate suspicious emails.
Change the font size
Change margin width
Change background colour