Skip to content
Skip to main content
Email Evidence Operational Explainer

How do I preserve and examine an attachment?

Preserve the complete native email before separating the attachment from it.

Then examine a verified working copy of the attachment using controls appropriate to the file type and risk.

Why this matters
An attachment is both a file and part of a particular message. Extracting the bytes may preserve the file, but the native message preserves the relationship to sender, recipient, delivery, filename and surrounding MIME structure.

Keep the attachment in context first

The message may record details such as:

  • displayed filename;
  • declared content type;
  • transfer encoding;
  • Content-ID;
  • whether the item was inline or attached; and
  • message and provider identifiers around the delivery event.

That relationship can matter later if you need to explain which version of a file was actually delivered to this recipient in this message.

Example attachment context
Filename: Invoice_10482.xlsmContent-Type: application/vnd.ms-excel.sheet.macroEnabled.12Content-Disposition: attachmentMessage-ID: <7f1a...@example>

The filename and declared content type are useful, but neither should be treated as proof of the true file format. Examination should establish what the content actually is.

Record what the recipient did

The attachment enquiry may change depending on whether the recipient:

  • only saw the filename;
  • previewed it;
  • downloaded it;
  • opened it;
  • enabled active content;
  • edited or saved it;
  • forwarded it; or
  • uploaded it somewhere else.

Record the approximate time, device and application where possible.

Those actions may create a second evidence trail on the endpoint, browser, mail client or security platform.

Separate preservation from risky examination

Do not open an executable, script, archive, macro-enabled document or unknown file on an ordinary workstation merely to see what happens.

Use the organisation's forensic, malware-analysis or security process appropriate to the risk.

A sensible sequence is:

1Preserve native emailKeep message and attachment relationship intact.
2Extract working copyRecord how the attachment was extracted and any hash required by local procedure.
3Identify file typeUse content and structure, not filename alone.
4Examine safelyUse controls suited to the file and suspected behaviour.

Keep security-platform evidence as a separate source

Mail gateways and security products may have their own:

  • file hashes;
  • verdicts;
  • quarantine records;
  • detonation or sandbox reports; and
  • records showing whether the item was delivered, sanitised, replaced or blocked.

Those records can be valuable, but keep them distinct from what the recipient's mailbox actually contained.

The practical point is: preserve the attachment in its original message context, then analyse a controlled working copy and keep the examination findings separate from the preserved source.

Sources

Reference: EML-011Email Evidence