The investigation library

Forensic resources

Practical reference material for domain investigations, suspicious-link analysis and evidence preservation. Grounded in technical standards, written for real investigations.

13 resources

Guide · 6 min read

Reading DMARC and SPF records

Interpret email authentication policy without confusing a DNS record with proof of message authenticity.

Read resource
Field note · 5 min read

RDAP, WHOIS and registration gaps

Understand registration events, redacted identity information and the limits of public domain records.

Read resource
Reference · 7 min read

DNS records: an investigator’s reference

A, AAAA, MX, TXT, CNAME, NS and SOA records, with their forensic significance and limitations.

Read resource
Pattern · 6 min read

Investigating lookalike domains

Examine typosquatting, brand impersonation and newly registered domains without jumping to conclusions.

Read resource
Guide · 5 min read

URL anatomy and deceptive links

Separate scheme, hostname, user information, path and query data when examining suspicious URLs.

Read resource
Method · 5 min read

Redirect chains and shortened links

Document intermediate destinations and understand why a final URL can vary between observations.

Read resource
Checklist · 6 min read

Phishing URL triage

A structured approach to suspected credential theft, malicious links and brand impersonation.

Read resource
Method · 5 min read

Passive DNS and domain change history

Compare historical observations without treating incomplete coverage as a complete timeline.

Read resource
Guide · 7 min read

Preserving domain and URL evidence

Record provenance, timestamps and collection limitations for defensible investigative findings.

Read resource
Field note · 5 min read

IP addresses, hosting and attribution

Distinguish network infrastructure from the person or organization operating a suspicious website.

Read resource
Investigation guide · 6 min read

Business email compromise investigation

What BEC is, how payment deception works and which email, domain and transaction evidence to preserve.

Read resource
Response checklist · 5 min read

Invoice fraud and payment diversion

Verify changed payment instructions, preserve invoice evidence and investigate supplier impersonation safely.

Read resource
Forensic reference · 5 min read

Email spoofing vs account compromise

Distinguish spoofed domains, lookalike senders and compromised mailboxes when investigating BEC.

Read resource