Email Threat Analysis: Reviewing Attachments Safely
2/4/2026A static only workflow for extracting, hashing, and inspecting email attachments without opening them.
when a problem repeats, i script it. when the script is useful, it lands here with setup, commands, and troubleshooting.
A static only workflow for extracting, hashing, and inspecting email attachments without opening them.
Shell commands to run when triaging a downloaded .eml file, with explanations of what each command and flag does.
Spin up a Raspberry Pi honeypot (OpenCanary), ship events to Azure Log Analytics with Fluent Bit, and verify it end‑to‑end.
Turn jumbled headers into a readable hop trail with SPF/DKIM/DMARC snapshots — evidence only.
When port 3000 is 'already in use', here’s the fast way to identify and free it on macOS, Linux, or Windows.
Tiny Python CLI to quickly check SPF, DMARC, MTA-STS, TLS-RPT, and optional DKIM selectors.