CYYDER CLARITY™ Framework | Category: 🟩 ENTERPRISE & CONTENT SECURITY
Lab 6 — Email Journey & Protection Decision Sandbox
💼 Business Scenario: An attacker is spoofing your corporate domain (executive@company.com) and sending a high-risk email containing a malicious PDF payload and a credential-harvesting link to an internal employee. At which stage of the inbound mail delivery pipeline will your security controls detect and block the attack, or will the phishing attempt reach the user's inbox?
Context ✔Landscape ✔Alignment ✔Risk & Control ✔Testing ✔
Inbound Email Simulation Engine
Header Fromceo@company.com
Envelope Fromattacker@spoofed-domain-external.com
Sender IP198.51.100.44
SubjectURGENT: Executive Payroll Update & Invoice Approval
AttachmentPayroll_Adjustment.docx
Embedded URL—
Body
Please approve the attached payroll adjustment immediately and confirm banking details.
Attack Vector Presets
Inbound Mail Pipeline — Live Telemetry
- 1Sender (External Internet)•⬇
- 2Domain Authentication (SPF / DKIM / DMARC)•⬇
- 3Secure Email Gateway (Anti-Spoofing & Reputation)•⬇
- 4Attachment Sandbox (Dynamic Detonation)•⬇
- 5Time-of-Click Link Inspection (Safe Links)•⬇
- 6Mailbox Ingestion (Exchange / M365)•⬇
- 7User Interaction (Click / Open)•⬇
- 8Endpoint Detection & Response (EDR)•
Email Defense & Policy Controls
L3/L4 DNS & Header Controls
Validates the sending IP against the domain's authorised sender list.
Cryptographic signature proving the message was not altered in transit.
Flags external mail impersonating internal executive display names.
Delivery Outcome
Dispatch the email to evaluate the current control posture.