What threat investigation actually takes, from three years in email security:
- End-to-end investigation: phishing, BEC, malware delivery, malicious URLs and attachments, spoofing, impersonation
- Evidence correlation: authentication headers, message trace, hop-by-hop path analysis, timeline reconstruction
- True vs. false positive calls, with proof
- Root cause analysis and harm assessment
- Data work: SQL, Python, regex, backend logs, APIs, stack traces
- Email and identity: SMTP, SPF, DKIM, DMARC, TLS, DNS, Microsoft 365, Google Workspace, OAuth2, SAML/SSO
- Data protection: DLP policy design and tuning, data classification
- AI: building agents, workflow automation, guardrail testing
- And the one nobody lists: explaining all of it so people act on it
Notice how little of that is "knowing which button to click."