Skip to content

Detect and Respond

Phishing Remediation

Takes a reported message from any source, works out who else got it, and removes it everywhere, once an analyst says go.

Audience
SOC analysts
Headline
Time to containment
Sources
Mail security, user reports
Output
Contained incidents

What it does

Inside Phishing Remediation

Multi-source phishing triage with enrichment, mailbox scoping, and analyst-gated remediation.

Multi-source intake

Detections from your mail security platform, messages users report themselves, and manual submissions all become one incident type.

Full indicator enrichment

Sender, reply-to, every URL, every attachment hash, and the sending infrastructure, all enriched before triage.

Mailbox scoping

Before anything is removed, the agent works out exactly which mailboxes received the message and who interacted with it.

Analyst-gated remediation

Purging mail, blocking a sender, and notifying recipients are proposed as a set of actions and wait for approval.

Reversible actions

A purge records how to restore. If a message turns out to be legitimate, the rollback is one action, not a support ticket.

Complete audit trail

Who approved what, when, on which mailboxes, and what the outcome was. Written once, never edited.

How it works

See, decide, act.

Every agent follows the same three movements. What differs is what it reads, what it scores, and what waits for a person.

  1. See

    A message worth looking at

    A detection fires, or a user reports something. Either way an incident opens with the full message and its headers.

    • Proofpoint TAP detection
    • Defender for Office 365 alert
    • A user report through KnowBe4
    • Manual submission
  2. Decide

    Scored, and scoped

    Indicators are enriched, the message is scored, and the blast radius is established: which mailboxes have it, and who clicked.

    • URL and attachment reputation
    • Sender infrastructure history
    • Mailbox recipient list
    • Click and interaction telemetry
  3. Act

    Removed everywhere, on approval

    The agent proposes the full remediation set. An analyst approves it, and it executes across every affected mailbox with a rollback recorded.

    • Soft-delete from all recipients
    • Add sender to the block list
    • Notify recipients who clicked
    • Hand the identity risk to Identity Compromise
1 / 3

Governance

How Phishing Remediation is governed

What always waits for a person differs meaningfully between agents, so it is stated per agent rather than as a platform-wide generality.

What it does on its own

Enriches every indicator, scopes the affected mailboxes, scores the message, and closes clean incidents.

What always waits for a person

Purging mail from any mailbox, blocking a sender tenant-wide, and notifying recipients all require analyst approval.

What it records

The full message, every indicator verdict, the mailbox scope, the approval, the executed actions, and the rollback path.

Alert Navigator

Detect and Respond · v2.0

Alert triage that separates true from false positives, groups related alerts into cases, and opens the ticket.


  • Pending triage
  • True positives
  • Tickets opened

Identity Compromise

Detect and Respond · v2.0

Account-takeover detection across sign-in, MFA, and audit telemetry, with containment on approval.


  • Under review
  • Accounts contained
  • Monitoring

Book a demo

See Phishing Remediation on your own data.