Academyby Dasow

Stop 8 of 9 · Set once

Research and security

Turn a CVE or a vendor advisory into a decision about your own kit, run the is-this-phishing check on forwarded mail, and write security tips people actually read.

Watch first · 1:03

Research that ends in a decision

Advisories are written for everybody, and Tariq only needs the part that touches his kit. A CVE lands in a Meraki firmware note or a Windows patch summary, and the question is never "how bad is this in general". It is "do we run that version, on how many machines, and does it wait until the next window".

Research mode is for this. It searches, reads the sources and gives you a cited answer, and the citations are the point: you follow the vendor advisory link and read the affected-versions table yourself before you act on any of it.

Trust Treat as a pointer only
The vendor's own advisory for the product Security vendor blog posts
The official CVE and NVD entry Aggregator news articles
Your own inventory export Forum comments and social posts
Turn an advisory into a decision about your kit
Research this advisory and tell me what it means for us specifically. Use the vendor advisory and the official CVE entry as your sources, and cite them.

Give me: the affected products and exact version ranges, whether it is being exploited in the wild and how you know, the fixed version, and the mitigation if we cannot patch this week. Then, against the inventory below, tell me which of our devices are in the affected range and which are not.

Grantham and Reed inventory: [paste your firmware and OS build list]
Advisory: [paste the advisory link or reference]

The phishing check

The check runs on headers, not vibes. Tariq forwards the suspect mail as an attachment so the original headers survive, copies the header block and the body text, removes his colleagues' names, and leaves the attachment closed.

Is this phishing
Below are the full headers and the body text of an email a user forwarded to the IT desk. The attachment is not included and will not be opened.

Tell me: what the actual sending domain and return path are, what SPF, DKIM and DMARC results the headers report, whether the display name matches the sending address, what the visible links resolve to, and any language pattern that points to a business email compromise attempt.

Finish with a verdict of phishing, suspicious or likely legitimate, the two facts that decide it, and what I should do in the next ten minutes if it is the first one.

[paste the headers and body]
Security tips in the firm's voice
Write four short security tips for the staff at Grantham and Reed, an accounting firm where people handle client financial records daily. Each tip is two sentences, names something they will genuinely see this month, and says exactly what to do. No scare language, no jargon, no percentages. Tone: a colleague who is on their side, not a compliance poster.

Quick check

Try it

Report a bug or share feedback