Phish Detect: Centralized SOC Email Ingestion & Automated Triage¶
Platform Feature:
Phish Detect
UI Location:Main Navigation > Live Threat Watch > Phish Detect (/phish-detect)
Core Capabilities: Centralized Threat Ingestion Mailbox, Automated Simulation Disambiguation, Severity Tiering
Associated Settings:Settings > Platform Management > Phishing Detection
1. Executive Summary & Value Proposition¶
When employees actively report suspicious emails, security operations centers (SOCs) face a massive operational challenge: triage overload. A company with 10,000 employees can generate hundreds of reported emails weekly. Over 90% of these submissions are either harmless spam, internal marketing newsletters, or authorized internal security simulations.
Phish Detect (/phish-detect) provides an automated ingestion and triage engine. It ingests reported emails in real time, automatically recognizes internal SimuPhish simulation drills to deliver instant positive feedback, and categorizes external malicious threats for immediate SOC investigation.
2. The Triage Workflow¶
sequenceDiagram
autonumber
actor Employee as Corporate Employee
participant AddIn as SimuPhish 1-Click Add-in
participant PhishDetect as Phish Detect Ingestion Mailbox (/phish-detect)
participant AI as AI Threat Analyzer
actor SOC as Security Operations Center
Employee->>AddIn: Clicks "Report Suspicious Email" in Outlook/Gmail
AddIn->>PhishDetect: Forwards full email with RFC headers & attachments
PhishDetect->>PhishDetect: Checks Cryptographic Simulation Token
alt Was An Authorized SimuPhish Drill
PhishDetect-->>Employee: Instant recognition toast: "Threat Neutralized!"
PhishDetect->>PhishDetect: Increments Employee Reporting Vigilance Score
else Was An Unknown External Email
PhishDetect->>AI: Trigger AI Header, Link & Attachment Inspection
AI-->>PhishDetect: Severity Classified (Malicious, Suspicious, Spam, Clean)
PhishDetect->>SOC: Routes to Incident Escalation Queue for Action
end
3. Key Business Benefits & SOC Value¶
- Cuts SOC Triage Time by 90%: Instantly filters out authorized simulations and benign newsletters.
- Empowers Employees: Closes the feedback loop with instant acknowledgment, encouraging continuous reporting vigilance.
- Centralized Mailbox Configuration: Configured under
Settings > Platform Management > Phishing Detection > Phish Detect Email Address.