The Email tab is in the Event Details panel. Here you can view a list of email received and associated attachments for an event.

Workflow

WkFlow-EmailRecon.png

Related Topics

Quick Look

The Email panel displays a list of emails associated with a network event. When an analyst opens the email, the email reconstruction is displayed along with the associated attachments and additional header details, if any.
The following figure is an example of an email reconstruction.

EmailRecon115.png

The following table describes all the fields within an email.

FieldDescription
FromDisplays the email address of the sender of the email.
ToDisplays the email addresses of the recipients of the email.
CC (Carbon Copy)Displays email addresses of additional recipients of the email. The field is displayed only if the sent email has any value and the email addresses are visible to the recipient.
BCCDisplays email addresses of additional recipients privately. This field is displayed only if the sent email has any value and the email addresses are not visible to the recipient.

Reply to

Displays the address designated to receive replies, the sender address.
SubjectDisplays the subject of the email.
AttachmentsDisplays any files shared by the sender that can be downloaded by the recipient. This field is displayed only if email contains attachments. See Download Data in the Events View for details about downloading email attachments.

Additional Header Details

Provides additional details of the email event such as Received, Sender, Message-ID and others.