Skip to content

Phish Detect: Centralized SOC Email Ingestion & Automated Triage

Platform Feature: Phish Detect
UI Location: Main Navigation > Live Threat Watch > Phish Detect (/phish-detect)
Core Capabilities: Centralized Threat Ingestion Mailbox, Automated Simulation Disambiguation, Severity Tiering
Associated Settings: Settings > Platform Management > Phishing Detection


1. Executive Summary & Value Proposition

When employees actively report suspicious emails, security operations centers (SOCs) face a massive operational challenge: triage overload. A company with 10,000 employees can generate hundreds of reported emails weekly. Over 90% of these submissions are either harmless spam, internal marketing newsletters, or authorized internal security simulations.

Phish Detect (/phish-detect) provides an automated ingestion and triage engine. It ingests reported emails in real time, automatically recognizes internal SimuPhish simulation drills to deliver instant positive feedback, and categorizes external malicious threats for immediate SOC investigation.


2. The Triage Workflow

sequenceDiagram
    autonumber
    actor Employee as Corporate Employee
    participant AddIn as SimuPhish 1-Click Add-in
    participant PhishDetect as Phish Detect Ingestion Mailbox (/phish-detect)
    participant AI as AI Threat Analyzer
    actor SOC as Security Operations Center

    Employee->>AddIn: Clicks "Report Suspicious Email" in Outlook/Gmail
    AddIn->>PhishDetect: Forwards full email with RFC headers & attachments
    PhishDetect->>PhishDetect: Checks Cryptographic Simulation Token

    alt Was An Authorized SimuPhish Drill
        PhishDetect-->>Employee: Instant recognition toast: "Threat Neutralized!"
        PhishDetect->>PhishDetect: Increments Employee Reporting Vigilance Score
    else Was An Unknown External Email
        PhishDetect->>AI: Trigger AI Header, Link & Attachment Inspection
        AI-->>PhishDetect: Severity Classified (Malicious, Suspicious, Spam, Clean)
        PhishDetect->>SOC: Routes to Incident Escalation Queue for Action
    end

3. Key Business Benefits & SOC Value

  • Cuts SOC Triage Time by 90%: Instantly filters out authorized simulations and benign newsletters.
  • Empowers Employees: Closes the feedback loop with instant acknowledgment, encouraging continuous reporting vigilance.
  • Centralized Mailbox Configuration: Configured under Settings > Platform Management > Phishing Detection > Phish Detect Email Address.