Cheat Sheets

Email Triage Cheat Sheet

email · triage · soc · cheat-sheet

📧 Email Triage Cheat Sheet

Quick reference for writing SOC email triage reports. Work through each section top to bottom.


⚠️ Blocking Warning

Before blocking IP addresses, remember: shared infrastructure like Gmail, Outlook/Microsoft 365, AWS, Azure, and Google Cloud is used by many legitimate services. Blocking their IPs can break business tools.

Prefer blocking these instead (more precise):


1) Email Description and Artefacts Collected

What this section is for:
Summarise what the email claims to be and list the key artifacts you collected.

Ask yourself:

Key artifacts to collect (most useful):

Sentence starters:


2) Artifact Analysis

What this section is for:
Record what you found when you checked each artifact (headers, URLs, attachment, infrastructure).

Ask yourself:

Key checks (keep it tight):

Sentence starters:


3) Suggested Defensive Measures

What this section is for:
Recommend containment and prevention actions based on the findings.

Ask yourself:

Common actions to recommend:

Sentence starters:


Keep this file handy during triage. Update it as your environment, tools, or reporting format changes.