Worked example: a suspicious attachment opened by the recipient¶
An employee receives an email containing what appears to be an overdue invoice.
They open the attachment. A warning asks them to enable active content. They accept it.
Nothing obvious happens.
At that point, do not get stuck analysing the email alone. The message tells you how the file arrived. The interesting question now is what the computer did after it was opened.
Fix the interaction time first¶
Start with the recipient.
Establish which device they used, which application opened the attachment, what warning appeared and what they clicked. Ask whether a browser opened, credentials were entered, another file appeared or anything else changed.
Do not ask them to reproduce the event.
Suppose the initial account is:
| Time | Event |
|---|---|
| 09:17:42 UTC | Email delivered to employee mailbox |
| 09:18:13 UTC | Attachment opened |
| 09:18:31 UTC | Recipient enables active content |
| 09:18:34 UTC onward | Relevant endpoint activity begins |
Those times give the technical examination a narrow window to work from.
Preserve the email and the attachment together¶
Keep the native message, its complete header and the attachment in their original relationship.
Record the displayed filename, file type where established, size, hash where generated by the examination process, and any security-platform result already held by the organisation.
How do I preserve and examine an attachment? covers the attachment-specific detail. The email preservation checklist covers the message, mailbox and provider layers.
The aim is to preserve the thing that was delivered and the context in which it arrived before the investigation moves onto the device.
Now follow the event onto the workstation¶
The endpoint records may show what happened immediately after the document was opened.
For example:
| Endpoint record | Why it matters |
|---|---|
| Word launches another process | Shows the document caused additional execution |
| New file appears in a temporary directory | May identify a downloaded or dropped payload |
| Process connects to an external address | Provides infrastructure and timing to investigate |
| EDR raises a detection | May identify behaviour, process IDs or a blocked action |
| Browser opens a new page | May show a redirect or credential-entry stage |
This is where timing really helps.
A suspicious process found somewhere on the computer is much less useful than a process chain beginning seconds after the preserved attachment was opened.
That is why the recipient's account of what they did is valuable even before the technical examination is complete.
The account may become part of the incident too¶
If credentials were entered, a session or token was obtained, or later mailbox activity looks unusual, preserve the account records as well.
Useful material may include:
- sign-ins and sessions;
- authentication or recovery changes;
- mailbox rules and forwarding;
- messages sent after the interaction;
- connected applications; and
- security alerts.
What account-access records may exist? explains those sources.
So one attachment can leave you with two useful trails to follow: what happened on the workstation, and what happened to the user's account afterwards.
Check whether other recipients received the same thing¶
The email-security platform may already know that the same attachment, URL, subject or sending infrastructure reached other users.
That can turn one reported message into a wider incident.
Search or preserve related messages using identifiers already present in the investigation: attachment hash, URL, Message-ID pattern, subject, sender infrastructure or a security detection.
If other recipients may still interact with the message, this becomes an immediate triage issue as well. Use the email evidence triage checklist to coordinate preservation and protection.
Record what the response team changes¶
The organisation may need to isolate the workstation, revoke account sessions, reset credentials or remove malicious material.
Those actions are often necessary, but they alter the device and account state.
Record who did what and when so the later reconstruction can separate:
- activity caused by the attachment;
- activity caused by the recipient; and
- activity caused by the incident response.
What can the investigation now say?¶
A useful conclusion might be:
The recipient opened the preserved attachment and enabled active content at approximately 09:18 UTC. Endpoint records then show the identified process and network activity beginning within the same event window.
That is far more informative than saying only that the attachment “looked malicious”.
It also leaves sensible next questions: what the process achieved, whether the account was affected, who sent the campaign and whether other devices or recipients were involved.
The practical rule is simple: once the attachment has been opened, follow the evidence onto the device. Keep the email because it gives you the trigger and the file. Then use the endpoint and account records to work out what it actually did.