Take any URLs, attachments, etc., to, Intelligent Classification and Protection, Managed Services for Security Awareness Training, Managed Services for Information Protection. Or if you log all outbound firewall requests, check for theIP address of the server that the site is running on. If the value is "unsupported", the messagePart is not supported by Attachment Defense and was not scanned. CVE-2022-28755 Talk to the clicker(s) This is a simple step that is sometimes overlooked. If you paste an IP into your browser, it will change it to a URL and go to the IP. Part of your phishing email incident response should be to make sure that you get the phishing email with full headers showing routinginfo,etc. In Outlook, youll have to look at the messages Properties in order to see all of the email routing information. In order to prevent other users from falling victim to the sameattack, look for attributes in the email that you can filter on. Depending on howthingsgo, you may need to save these logs and handle them in a waythat will stand up in court. Here is our list of 14 things you need to do when it happens: You do have a phishingincident response plan, right? Wouldnt it be great if instead of a Pavlovian response to click on anything in their inbox, your userspaused for even 500 milliseconds and though, Wait a seccould this be a PHISH? Use phishing tests and security awareness training to your advantage. Ifpossible, search on the message ID, source IPs, From, Subject, file Attachment name, etc. Rather, put the IP address in quotes to ensure that your browser knows you are just searching. Theres a reason, after all, that high schools put wrecked cars out front of their buildings during prom season. 