Start with evidence, not suspicion
The workflow separates evidence collection from judgment, so an urgent tone or alarming display name does not decide the case.
Documentation and workflow design
A guide for collecting evidence, assessing reported email, assigning severity, escalating consistently, and recording a decision another analyst can understand.
Vector interface mark · no raster artwork
My role
Technical writer, workflow designer, information architect, and interaction designer
Audience
Security analysts, service desk specialists, and developing incident responders
Artifact
Interactive playbook, header-analysis reference, and printable quick guide
Focus
Evidence-led decisions, consistent escalation, and defensible case notes
The documentation problem
A reported message may be harmless spam, a credential lure, malware, or the first sign of account compromise. The playbook gives analysts evidence-based steps instead of relying on “looks weird.”
Documentation decisions
The workflow separates evidence collection from judgment, so an urgent tone or alarming display name does not decide the case.
Assign risk after reviewing sender context, authentication, links, attachments, and recipient actions.
The sample teaches a repeatable method and keeps approved incident-response procedures authoritative.
Experienced analysts can scan the quick reference. Newer analysts can open explanations and examples.
Use this playbook when an employee, automated control, or shared mailbox reports a suspicious email. The workflow supports consistent evidence collection and decision-making; approved organizational procedures remain authoritative for containment and incident response.
Standardize suspicious-email triage, severity, escalation, and case documentation.
Security analysts and service desk specialists with approved analysis access.
A message is reported, detected, or submitted for legitimacy and risk review.
Confirmed compromise, malware incidents, payment loss, or cases already owned by incident response.
Confirm access to the original message or full headers, approved URL and attachment analysis tools, mailbox search or security tooling, the ticketing system, and the current escalation path.
Current stage
Capture the message and the reporter’s context before links, attachments, or mailbox actions change the available evidence.
A stable evidence set and an initial exposure statement.
This teaching aid produces a starting recommendation, not an automated verdict. Analysts should preserve uncertainty and follow local severity definitions.
No malicious indicators were identified. The message may be legitimate, unwanted marketing, or ordinary spam.
Document the rationale, advise the reporter, and close according to local procedure.
The message contains unusual characteristics, but available evidence does not support a malicious disposition.
Record uncertainty, verify through a trusted channel when appropriate, and monitor for related reports.
Evidence supports phishing, impersonation, credential harvesting, or another malicious attempt without confirmed recipient compromise.
Follow approved blocking or purge procedures, search for related messages, and notify affected recipients as required.
Recipient interaction, malware, payment manipulation, account compromise, broad delivery, or privileged targeting creates immediate risk.
Escalate immediately and begin the organization’s incident-response or containment process.
The identity mismatch, credential request, and destination support a phishing disposition. No recipient impact is confirmed, so the attempt is Medium rather than High.
Apply approved message containment, search for additional recipients, block relevant indicators, and notify the reporter.
Compare the visible name with From, Reply-To, Return-Path, and the actual business context.
Use SPF, DKIM, and DMARC as evidence. A malicious domain can pass its own authentication checks.
Use approved analysis tools and preserved evidence rather than interacting from the recipient’s mailbox or production device.
A click, credential entry, OAuth approval, opened attachment, reply, or payment action can change both severity and response.
Record the indicators, context, limitations, and why they support the final disposition.
Search for related messages and reports before treating a single mailbox as the full incident boundary.
Authentication can pass on infrastructure controlled by an attacker.
Legitimate forwarding, third-party senders, and mailing platforms can complicate identity and authentication signals.
Reputation tools may have no data for new infrastructure and can lag behind emerging campaigns.
A polished message with correct grammar may still be malicious, while an awkward message may still be legitimate.
Screenshots can hide destinations, headers, attachments, and other evidence needed for a complete assessment.
This public sample cannot define organization-specific containment authority, tooling, legal obligations, or escalation contacts.
Work sample boundary
This independent portfolio simulation shows my approach to technical writing, workflow documentation, information architecture, and security-aware communication. It does not reproduce a private employer playbook or replace approved incident-response procedures.