A reported phishing message is confirmed malicious - how do you scope who else in the tenant got it?
answer
- one report is a sample of a send
- subjects vary, infrastructure does not
- open the window before the report
- delivery is not interaction
- silence from recipients is not safety
basics
~20 sSearch the mail trail on the campaign's stable elements, not the exact subject, over a window that opens before the report. Then split recipients into those who merely received it and the few with evidence of acting.
solid answer
~50 sOne report is a sample, and its real value is the other recipients. I pivot from the confirmed copy to the elements that survive across a campaign - the sending infrastructure, the sender domains, the URL host and path pattern, an attachment hash, an application client id - because subjects, greetings and display names are usually personalised per recipient, so an exact-subject search finds a fraction of the send. The window opens **before** the report, since the reporter is rarely the first recipient, and stays open forward because the campaign may still be arriving. Then I split the recipient list, because delivery is not interaction: the people I chase are the ones with evidence of acting - a sign-in or consent event at the identity provider, a resolution or proxy hit for the lure host - and I rank the rest by what their access is worth. Silence from the other 239 is not evidence they did nothing.
go deeper
Know that a single reported message is scoped across the whole tenant rather than treated as one mailbox, and that the point is finding everyone else who received the same thing.
Explain which elements survive per-recipient personalisation and which do not, why the window opens before the report, and why the mail trail alone cannot tell you who interacted.
Demonstrate the cross-surface interaction verdict, refreshing scope on a live campaign, and ranking 240 recipients sensibly when you cannot work them individually.
Own the precondition: this pivot is only possible in minutes if the mail, identity and web telemetry and their retention were bought and joined up beforehand, and that is a budget conversation you have long before the report arrives.
## What the report is actually worth A reported message tells you one thing on its face: this mail reached this mailbox and one person found it odd. Its value is almost entirely indirect. The same mail was sent to a list, most of that list did not report it, and the copies are still sitting in inboxes while you read the header block. Scoping - establishing the true recipient set - is therefore the first move after the verdict, and it is time-critical in a way the verdict itself is not. ## Building the search from one copy Split the confirmed message into elements that vary and elements that do not. **Varies per recipient:** subject line, greeting, display name, the personalised path or token in a URL, sometimes the sender's local part. Searching on any of these finds a slice of the campaign and hides the rest, and it is the most common scoping failure. **Stable across the campaign, usually:** the sending IP addresses and the networks they belong to, the sender domain or its registration pattern, the URL host, the path structure once the per-recipient token is stripped, an attachment hash, and for a consent lure the application client id. These are your search terms. It is worth being precise about what these are. The sending IP, the URL host and the file hash are **indicators**: artefacts observed in this campaign, easy for the sender to change tomorrow. The behaviour - a mail from a domain registered this week, carrying a link to an authorisation request, sent to hundreds of recipients at once - is a **description of how they operate**, and it is what you fall back on when the campaign rotates its infrastructure mid-send, which competent ones do. Start from the indicators because they are cheap and exact; keep the behavioural search ready because the indicator set goes stale during the incident. ## The window, in both directions Open the search comfortably before the reported message's timestamp. The reporter is rarely the first recipient - people read mail at different times, and some campaigns seed a few mailboxes hours before the main send. Keep the window open going forward, too: a campaign in progress keeps delivering while you scope, so a scope taken once and never refreshed goes stale within the hour. Re-run it before you declare the recipient list final. ## Delivery is not interaction The mail trail can tell you that a message was accepted for a mailbox and where it went. It cannot tell you that a human read it, and it certainly cannot tell you that anyone clicked. Those answers live on other surfaces, and reaching for them is what separates a scoped case from a list of names: - **Identity provider sign-in and consent records** for the recipients in the window - an authentication from unfamiliar infrastructure, or a grant to the application the mail was pushing. - **DNS and proxy records** for the lure host, which show which internal clients resolved or fetched it. - **Endpoint telemetry**, if an attachment was involved, for what was written and executed. And the direction of those claims matters. A resolution proves a lookup happened, not that a person typed a password. An absence of any of these in an estate with known telemetry gaps is weak evidence rather than proof of safety. ## Ranking, when you cannot chase everyone Two hundred and forty recipients is more than one analyst can work individually. Rank by three things: evidence of interaction first; then what the account can reach, which puts finance approvers, administrators and executive assistants near the top; then whether copies are still deliverable and unread. The people with no interaction evidence and ordinary access are a communication problem, not an investigation. ## The 239 who said nothing One report out of 240 recipients is itself a measurement - of how far the report button has reached, and of how long a campaign can sit in this estate before somebody speaks. Do not read the silence as safety. It is also worth thinking about how you contact the rest: a mass mail warning everyone about a suspicious mail is itself a mail with urgency and a request in it, arriving from an unfamiliar internal sender, and it gets ignored or reported in turn. Specific, short, and where possible via a channel other than the one under attack. ## What your scope hands over The product of this work is a recipient list with an interaction verdict per person, a time window, and the indicator set that produced it. Removing the remaining copies, and containing any account that acted, are the next people's steps - but they cannot start until your list exists, which is why scoping is the work that sits directly between a verdict and a response.
- The subject line differs in every copy - what do you search on?The elements that survive personalisation: sending addresses and their networks, the sender domain pattern, the URL host and the path structure with the per-recipient token stripped, an attachment hash, or the application client id. When the campaign rotates infrastructure mid-send, fall back to a behavioural search - newly registered sender domain, same link shape, many recipients at once.
- The mail trail shows delivery to 240 mailboxes - how many accounts are compromised?Unknown from that record. Delivery establishes that the message arrived and nothing more. Compromise needs evidence from other surfaces: a sign-in or consent event at the identity provider, a resolution or proxy fetch for the lure host, endpoint activity if a file was involved. And an absence of those, in an estate with telemetry gaps, is weak evidence rather than proof.
- How do you warn the remaining recipients without the warning being ignored?Keep it short and specific - the exact subject shape, the sender, what to do if they interacted - and prefer a channel other than the one under attack, since a broad urgent mail from an unfamiliar internal sender looks exactly like the thing you are warning about. Give the people with interaction evidence a direct conversation instead of a broadcast.
saying these in an interview costs you the question
- Searches only for the exact subject line
- Starts the search window at the moment of the report
- Reads delivery in the mail trail as compromise
- Assumes the recipients who did not report were unaffected
- Works the reporter's mailbox and closes the case
- Takes the scope once and never refreshes it while the campaign is live