Email Monitoring Flashcards
Spear Phishing
An email spoofing attack targeting a specific organization or individual by
seeking unauthorized access to sensitive information
BEC
An impersonation attack in which the attacker gains control of an
employee’s account and uses it to convince other employees to perform
fraudulent actions
Forwarding
When a phishing email is formatted to appear as if it has come as part of
a reply or forward chain
Email Internet Header
A record of the email servers involved in transferring an email message
from a sender to a recipient
Exploit 3 address fields in email
Display From Support@diontraining.com theft@badguy.com
Envelope From Various labels hidden from mail client
Received From/By List of the MTAs that processed email
Email Server Security
Spoofing attacks can be mitigated by configuring authentication for email server
systems. SPF, DKIM, and DMARC do not solve the problem of cousin domains
SPF
DNS record identifying hosts authorized to send mail for the domain with
only one being allowed per domain
DKIM
Provides a cryptographic authentication mechanism for mail utilizing a
public key published as a DNS record
DMARC
A framework for ensuring proper application of SPF and DKIM utilizing a
policy published as a DNS record
SMTP Log analysis codes
Code 220 indicates the server is ready
Code 250 indicates the message is accepted
Code 421 indicates the service is not available
Code 450 indicates that the server cannot access the mailbox to deliver a
message
Code 451 indicates the local server aborted the action due to a
processing error
Code 452 indicates the local server has insufficient storage space
available
S/MIME
An email encryption standard that adds digital signatures and public key
cryptography to traditional MIME communications
Email Content Analysis
An attacker must also craft some sort of payload to complete the exploit when a
victim opens a message
MIME
Allows a body of an email to support different formats, such as HTML,
rich text format (RTF), binary data encoded as Base64 ASCII characters,
and attachments