Security & Privacy · THE NO-PANIC PLAN
Record a suspicious URL or file indicator without opening it
Use this bounded process when someone reports a suspicious URL, domain, IP address, or file hash and your role is to document it safely. Do not click, paste into a browser, resolve, download, or test the indicator. A text record is not a malware verdict, and a reputation result is not proof that a destination is safe. If anyone already opened the link, entered credentials, approved a prompt, or downloaded a file, switch to your organization?s incident-response process immediately.
MISSION Help a responder capture a suspicious URL, domain, IP address, or file hash as inert evidence, preserve where it came from, and hand it to an authorized security process without visiting the destination.
Record the indicator safelyTHE REAL-WORLD BIT
What happens outside this browser tab?
Preserve the original report in an authorized case system; copy the indicator as non-clickable text with its exact type and provenance; record UTC time, context, and confidence without exposing tokens or personal data; use only your organization-approved analysis and reporting path; then verify the case record and next owner. Never make the indicator an active link or visit it to validate it.
YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES
One step at a time.
Follow the order below. If a step names a Nirmion tool, its link is right there with it.
- 01
Open a case from the report, not from the indicator
Use your employer?s approved security-reporting button, ticket queue, or incident case system. Keep the original message or alert as an attachment in the controlled evidence location when policy permits; an exported .eml or .msg can preserve useful headers, but handle it only with approved tools. Record who reported it, when they reported it, how it arrived, which account or device was involved, and whether anyone clicked, replied, entered a password, approved MFA, or opened an attachment. Do not click the link, copy it into a browser, preview the destination, or ask the reporter to test it. If an interaction already happened, notify the security team through its incident route before doing routine documentation.
- 02
Capture the indicator as inert text and label its type
Transcribe only the needed observable from the original message or trusted alert: full URL, hostname/domain, IP address, file name, or cryptographic hash. Preserve the exact original separately as restricted evidence if your process requires it; create the working/display copy with a harmless defanging convention such as hxxps://example[.]invalid so it cannot be clicked accidentally. Label the type and source explicitly, distinguish a copied value from an analyst inference, and do not silently normalize, decode, resolve, shorten, or remove URL parameters. Query strings can contain session tokens, email addresses, reset codes, or other secrets: keep them in the restricted evidence record, redact them from routine notes, and follow the incident team?s procedure for handling the full value.
- 03
Add provenance, time, and confidence without changing evidence
For each value, record the source record or attachment identifier, collection time in UTC (retain the original displayed time and timezone when useful), reporting channel, affected account/device if authorized, and the exact field where it appeared. Mark whether it is directly observed, reported by another person, or derived from a security alert; include the alert/case ID and confidence supplied by that system without treating it as a confirmed verdict. Preserve a hash or read-only original when required by policy and avoid editing the source message. Remove unrelated recipient data and credentials from working notes. Never upload a private or organization-specific URL, email, attachment, or indicator to a public scanner or shared document unless the security owner has explicitly approved that service and data disclosure.
- 04
Hand it to the authorized analysis path
Follow the organization?s incident-response plan and access rules. A trained administrator may submit a suspicious URL or message through an approved vendor portal if policy allows; for example, Microsoft documents URL and email submissions in its Defender portal, with role requirements and separate choices for a suspected item versus a confirmed threat. Submit only the values and evidence the approved workflow needs. Do not create a block rule, allow-list entry, or external report merely because a value looks suspicious; those actions can affect users and require the designated owner. For a sanitized sequence of observed events, Security Incident Timeline Builder ID 11714 can organize dates and event labels locally; leave URLs, email addresses, credentials, and other sensitive indicators out of the tool.
- 05
Verify the record and assign the next action
Re-open the case record using its case ID and check that the indicator is displayed as non-clickable text, its type and provenance are present, timestamps retain their timezone meaning, and no password, reset token, or unnecessary personal data was copied into the ordinary note. Confirm the authorized owner accepted the handoff, record any vendor submission or internal analysis reference, and state the next action and due time. A pending or inconclusive reputation result does not establish safety; keep the case open until the owner records a disposition or further investigation. If the reporter clicked, disclosed credentials, or ran a file, follow the response plan for containment, account protection, evidence preservation, and required notifications.
THE HELPER CREW
Tools for the fiddly bits.
These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.
RECEIPTS, PLEASE
Sources & review notes
Each source is linked to the steps it supports. Open it to check its scope and current guidance.
Source checked 2026-10-05