NewKnowledge base governance playbook is live
Back to work
Technical writing work samplePublic-safe simulation

Documentation and workflow design

Suspicious EmailTriage Playbook

A guide for collecting evidence, assessing reported email, assigning severity, escalating consistently, and recording a decision another analyst can understand.

Vector interface mark · no raster artwork

My role

Technical writer, workflow designer, information architect, and interaction designer

Audience

Security analysts, service desk specialists, and developing incident responders

Artifact

Interactive playbook, header-analysis reference, and printable quick guide

Focus

Evidence-led decisions, consistent escalation, and defensible case notes

The documentation problem

Standardize how analysts investigate the same report

A reported message may be harmless spam, a credential lure, malware, or the first sign of account compromise. The playbook gives analysts evidence-based steps instead of relying on “looks weird.”

Documentation decisions

Use the page structure to support the instruction

01

Start with evidence, not suspicion

The workflow separates evidence collection from judgment, so an urgent tone or alarming display name does not decide the case.

02

Put severity after analysis

Assign risk after reviewing sender context, authentication, links, attachments, and recipient actions.

03

Keep the authority boundary visible

The sample teaches a repeatable method and keeps approved incident-response procedures authoritative.

04

Support scanning and deep work

Experienced analysts can scan the quick reference. Newer analysts can open explanations and examples.

Security Knowledge BaseTechnical writingSuspicious Email Triage
Portfolio sample · v1.0
Playbook overview

Investigate the message. Document the decision.

Use this playbook when an employee, automated control, or shared mailbox reports a suspicious email. The workflow supports consistent evidence collection and decision-making; approved organizational procedures remain authoritative for containment and incident response.

Purpose

Standardize suspicious-email triage, severity, escalation, and case documentation.

Primary audience

Security analysts and service desk specialists with approved analysis access.

Use when

A message is reported, detected, or submitted for legitimacy and risk review.

Do not use alone for

Confirmed compromise, malware incidents, payment loss, or cases already owned by incident response.

Before you begin

Confirm access to the original message or full headers, approved URL and attachment analysis tools, mailbox search or security tooling, the ticketing system, and the current escalation path.

Core workflow

Eight stages, one defensible path.

Select a stage
01

Current stage

Preserve the report

Capture the message and the reporter’s context before links, attachments, or mailbox actions change the available evidence.

  • Record reporter, recipient, subject, sender, and received time.
  • Preserve full headers or original message source when available.
  • Ask whether the recipient clicked, replied, opened an attachment, entered credentials, approved MFA, or sent money.
Stage output

A stable evidence set and an initial exposure statement.

Guided decision tree

Practice combining impact, scope, and evidence.

This teaching aid produces a starting recommendation, not an automated verdict. Analysts should preserve uncertainty and follow local severity definitions.

1What did the recipient do?
Severity definitions

Describe the risk without collapsing every case into “phishing.”

InformationalBenign or unwanted

No malicious indicators were identified. The message may be legitimate, unwanted marketing, or ordinary spam.

  • Expected notification
  • Benign mailing list
  • Unwanted solicitation
Response

Document the rationale, advise the reporter, and close according to local procedure.

LowSuspicious, unconfirmed

The message contains unusual characteristics, but available evidence does not support a malicious disposition.

  • Unexpected vendor message
  • Authentication anomaly with verified sender
  • Poorly configured legitimate mail
Response

Record uncertainty, verify through a trusted channel when appropriate, and monitor for related reports.

MediumLikely malicious attempt

Evidence supports phishing, impersonation, credential harvesting, or another malicious attempt without confirmed recipient compromise.

  • Credential lure
  • Fake document-share page
  • QR-code phishing
  • Brand impersonation
Response

Follow approved blocking or purge procedures, search for related messages, and notify affected recipients as required.

HighImpact or urgent campaign

Recipient interaction, malware, payment manipulation, account compromise, broad delivery, or privileged targeting creates immediate risk.

  • Credentials entered
  • Malware executed
  • Payment details changed
  • Executive or vendor compromise
  • Multi-recipient campaign
Response

Escalate immediately and begin the organization’s incident-response or containment process.

Escalation criteria

Escalate when the possible impact outruns routine triage.

!
  • Credentials were entered, an OAuth grant was approved, or MFA prompts were accepted.
  • Money, gift cards, tax data, payment details, or sensitive records were sent.
  • An attachment was opened or malware execution is suspected.
  • The message targets executives, finance, payroll, administrators, or other privileged roles.
  • Multiple recipients received the same malicious message or campaign indicators are present.
  • A trusted internal or vendor account appears compromised.
  • The analyst cannot safely contain the issue within the playbook’s defined authority.
Worked examples

Show the reasoning, not only the label.

Expand a case
Evidence
  • Display name imitates Human Resources.
  • From domain is a newly observed lookalike.
  • Link resolves to a credential-collection page outside the expected service.
  • Recipient reports no interaction.
Reasoning

The identity mismatch, credential request, and destination support a phishing disposition. No recipient impact is confirmed, so the attempt is Medium rather than High.

Action

Apply approved message containment, search for additional recipients, block relevant indicators, and notify the reporter.

Common analyst mistakes

Shortcuts that make a decision harder to defend.

Trusting the display name

Compare the visible name with From, Reply-To, Return-Path, and the actual business context.

Treating authentication as a verdict

Use SPF, DKIM, and DMARC as evidence. A malicious domain can pass its own authentication checks.

Clicking to see what happens

Use approved analysis tools and preserved evidence rather than interacting from the recipient’s mailbox or production device.

Ignoring recipient actions

A click, credential entry, OAuth approval, opened attachment, reply, or payment action can change both severity and response.

Writing a conclusion without reasoning

Record the indicators, context, limitations, and why they support the final disposition.

Overlooking campaign scope

Search for related messages and reports before treating a single mailbox as the full incident boundary.

Known limitations

Signals help. Context still matters.

  1. 01

    Authentication can pass on infrastructure controlled by an attacker.

  2. 02

    Legitimate forwarding, third-party senders, and mailing platforms can complicate identity and authentication signals.

  3. 03

    Reputation tools may have no data for new infrastructure and can lag behind emerging campaigns.

  4. 04

    A polished message with correct grammar may still be malicious, while an awkward message may still be legitimate.

  5. 05

    Screenshots can hide destinations, headers, attachments, and other evidence needed for a complete assessment.

  6. 06

    This public sample cannot define organization-specific containment authority, tooling, legal obligations, or escalation contacts.

Governance and maintenance

A playbook is a maintained product.

OwnerSecurity Operations
Review cadenceQuarterly
Urgent updatesAfter material threat or tooling change
Feedback sourceAnalyst questions, misses, false positives, and incident review
Required case recordTRIAGE-NOTE
Reporter and recipient
Message subject and timestamps
Sender and relevant domains
Recipient actions
Authentication findings
Link or attachment findings
Indicators and campaign scope
Severity and confidence
Actions and escalation
Final disposition and analyst
VersionDateChange
1.0August 2026Initial public portfolio release
NextPlannedUsability review, scenario expansion, and approved pictogram artwork

Work sample boundary

This independent portfolio simulation shows my approach to technical writing, workflow documentation, information architecture, and security-aware communication. It does not reproduce a private employer playbook or replace approved incident-response procedures.