email-forensics

Extract forensic artifacts from PST, OST, MBX, EML, and MSG email files.

Updated Mar 30, 2026
One-click install
npx skills add https://github.com/erlebach/gordon --skill email-forensics-erlebach
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: email-forensics
Source: https://github.com/erlebach/gordon/tree/main/skills/email-forensics
Command: npx skills add https://github.com/erlebach/gordon --skill email-forensics-erlebach

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Email investigations require collecting messages from multiple formats, parsing content, and extracting artifacts to establish a credible timeline and evidence.

Core Features & Use Cases

  • Mailbox parsing: PST, OST, MBOX, EML, MSG to extract messages and metadata
  • Header and routing analysis: detect phishing, spoofing, and authentication results
  • Artifact generation: timelines, threads, attachments, and IOCs for reporting
  • Use case: Investigate phishing campaigns, BEC incidents, or insider threats using mailbox-wide analyses.

Quick Start

Provide a mailbox or email file and request a forensic analysis and a comprehensive report.

Frequently Asked Questions about email-forensics

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I extract forensic artifacts from PST and EML files for a phishing investigation?

Extract forensic artifacts from PST, OST, MBOX, EML, and MSG files by parsing mailbox data to detect phishing, spoofing, and BEC indicators. Apply the analysis to individual emails or archives to generate metadata timelines and threat reports.

What is the best way to detect email spoofing and BEC indicators in a mailbox archive?

Detect email spoofing and BEC indicators by performing header and routing analysis on mailbox archives. This process examines authentication results and metadata anomalies to identify malicious messages and reconstruct evidence-ready timelines.

Can I reconstruct an email timeline and thread history from MBOX and MSG formats?

Reconstruct email timelines and thread history from MBOX and MSG formats by parsing message metadata and content. This forensic analysis establishes a credible sequence of events for incident response and evidence collection.

Does email forensics analysis support exporting IOCs and attachments for incident reporting?

Email forensics analysis supports exporting IOCs, attachments, and reconstructed threads for incident reporting. It generates comprehensive reports from parsed mailbox data, with optional threat intelligence integrations for deeper investigation.

How do I analyze email headers to find routing anomalies and authentication failures?

Analyze email headers to find routing anomalies and authentication failures by examining the message transmission path. This forensic process detects spoofing attempts and metadata inconsistencies across mailbox archives.

What email formats are supported for parsing metadata and extracting investigation evidence?

Supported email formats for parsing metadata and extracting investigation evidence include PST, OST, MBOX, EML, and MSG. Robust parsing handles individual messages, full mailboxes, and archives to identify forensic artifacts.