Email Threat Analysis: Reviewing Attachments Safely
2/4/2026A static only workflow for extracting, hashing, and inspecting email attachments without opening them.
playbooksemailemail-threat-analysisincident-responseforensicsattachments
when a problem repeats, i script it. when the script is useful, it lands here with setup, commands, and troubleshooting.
A static only workflow for extracting, hashing, and inspecting email attachments without opening them.
Shell commands to run when triaging a downloaded .eml file, with explanations of what each command and flag does.
Turn jumbled headers into a readable hop trail with SPF/DKIM/DMARC snapshots — evidence only.
Tiny Python CLI to quickly check SPF, DMARC, MTA-STS, TLS-RPT, and optional DKIM selectors.