Multi-source intake
Detections from your mail security platform, messages users report themselves, and manual submissions all become one incident type.
Detect and Respond
Takes a reported message from any source, works out who else got it, and removes it everywhere, once an analyst says go.
What it does
Multi-source phishing triage with enrichment, mailbox scoping, and analyst-gated remediation.
Detections from your mail security platform, messages users report themselves, and manual submissions all become one incident type.
Sender, reply-to, every URL, every attachment hash, and the sending infrastructure, all enriched before triage.
Before anything is removed, the agent works out exactly which mailboxes received the message and who interacted with it.
Purging mail, blocking a sender, and notifying recipients are proposed as a set of actions and wait for approval.
A purge records how to restore. If a message turns out to be legitimate, the rollback is one action, not a support ticket.
Who approved what, when, on which mailboxes, and what the outcome was. Written once, never edited.
How it works
Every agent follows the same three movements. What differs is what it reads, what it scores, and what waits for a person.
How it works
See
A detection fires, or a user reports something. Either way an incident opens with the full message and its headers.
Decide
Indicators are enriched, the message is scored, and the blast radius is established: which mailboxes have it, and who clicked.
Act
The agent proposes the full remediation set. An analyst approves it, and it executes across every affected mailbox with a rollback recorded.
Security Overview
Governance
What always waits for a person differs meaningfully between agents, so it is stated per agent rather than as a platform-wide generality.
Enriches every indicator, scopes the affected mailboxes, scores the message, and closes clean incidents.
Purging mail from any mailbox, blocking a sender tenant-wide, and notifying recipients all require analyst approval.
The full message, every indicator verdict, the mailbox scope, the approval, the executed actions, and the rollback path.
Detect and Respond · v2.0
Alert triage that separates true from false positives, groups related alerts into cases, and opens the ticket.
Detect and Respond · v2.0
Account-takeover detection across sign-in, MFA, and audit telemetry, with containment on approval.