Skip to content
Abdullah

Project · 2026

Phishing Analyzer

An email-forensics tool for inspecting raw .eml files, validating authentication, detecting spoofing, enriching IOCs, and preparing incident reports. It gives analysts a cleaner path from suspicious email to useful next steps.

Role

Security Tool Developer

Status

live

Stack

Python, TypeScript, Next.js, SPF, DKIM, DMARC, IOC Enrichment, Groq AI

Overview

Phishing Analyzer is a browser-based forensics tool for moving from a suspicious email sample to a structured investigation without leaving a single interface. It is built for SOC analysts who need to triage phishing emails quickly, reach defensible conclusions, and document findings in a format that can go directly into a ticket.

The Problem

Investigating a suspicious email manually means checking authentication headers in one tool, validating SPF, DKIM, and DMARC records in another, extracting IOCs by hand, enriching them in a third tool, and then writing up findings somewhere else entirely. Each step is a context switch. Under alert volume, that process degrades.

Capabilities

Email Header Inspection — Upload a raw .eml file. The tool parses the full header chain, including routing hops, authentication results, originating server data, and X-headers, and presents everything in a readable, structured format rather than a wall of raw text.

SPF / DKIM / DMARC Validation — Performs real DNS lookups against the sending domain, not simulation or cached data. Results are surfaced with clear pass / fail / softfail / neutral status alongside the resolved records so the analyst can see exactly what the DNS configuration says.

Spoofing Detection — Checks for display-name spoofing, cousin domain lookalikes, homograph attacks (Unicode character substitution that survives visual inspection), and mismatches between the envelope From address and the header From address. Each finding is flagged with an explanation of why it is suspicious.

IOC Extraction and Enrichment — Pulls IPs, domains, URLs, and file hashes from the message body and headers automatically, then enriches them against threat intelligence sources.

AI Incident Report Generation — Groq synthesizes the full analysis into a structured incident report — context, findings, IOCs, recommended actions — in a format that can be pasted directly into a ticketing system without editing.

Technical Decisions

The parsing and DNS validation layer is written in Python, handling the complexity of RFC 5322-compliant header parsing and live DNS resolution. The frontend is TypeScript on Next.js.

Homograph detection uses Unicode normalization (NFKC) to catch look-alike characters — the kind that survive visual inspection because a Cyrillic 'а' looks identical to a Latin 'a' at normal font sizes. The AI report is prompted with the structured analysis output rather than the raw email, so it generates investigation-quality findings rather than generic descriptions.

Outcomes

  • Live at phishing-analyzer-abd.vercel.app
  • Part of the active SOC analyst portfolio alongside the IOC Enricher
  • Demonstrates a real-world email forensics workflow built on actual DNS lookups, not mocked data