PHISHING & EMAIL THREAT ANALYSIS
25:00
0 / 120 pts
READY
Target Environment
Command Reference

Complete an objective to see a command breakdown here.

OmniAegis — SOC Analyst Training
soc-ws-01 — bash
LIVE
Active Objective — Recon — List Suspicious Inbox
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
OmniAegis SecureStation v4.2 — SOC Analyst Terminal
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Session: 2026-08-28T22:35:59.094Z
Host: soc-ws-01.acmecorp.local
OS: Ubuntu 22.04 LTS — bash 5.1
Mission: Phishing & Email Threat Analysis
Clearance: UNCLASSIFIED // FOR TRAINING
Type 'help' for available commands. Follow objectives in the Mission Commander panel.
analyst@soc-ws-01:~$ 
OmniAegis SecureStation
UNCLASSIFIED // FOR TRAINING ONLY
LIVE
INCIDENT RESPONSE // THREAT ANALYSIS

Phishing & Email Threat Analysis

STEPS
0/7
POINTS
0
DIFF
BEGINNER
MISSION PROGRESS0%
ATT&CK Chain
T1566.001
Phishing: Spearphishing Attachment
T1059.007
JavaScript Execution
T1071.001
Web Protocols C2
🛡️Cyber Defense
SECTOR
Intel Brief

INTEL REPORT: Three suspicious emails were flagged by the organization's mail gateway at 03:47 UTC. Users in Finance have been targeted. Your mission is to triage the inbox, extract email artifacts, analyze headers for spoofing indicators, and quarantine confirmed phishing messages. Document all IOCs for the threat intelligence team.

Objective Roadmap
Visualemail header
From: ceo@acme.comReply-To: billing@evil.xyzSPF: FAIL · DKIM: noneSPOOFEDheader anatomy
Why: Email Triage

The first step in any phishing investigation is examining the inbox structure. Phishing emails often have telltale signs in their filenames, timestamps, or sender metadata before you even open them.

Objective

List the contents of the phishing samples directory to identify all staged email files.

Hint
Try: ls -la /opt/samples/phishing/
OMNI AEGIS TRAINING
25m EST.