Triaging what staff report to the phishing mailbox

Reads each message forwarded to the report-phishing address, pulls sender, headers, links and attachments out of the raw source, collapses reports of one campaign into a single case, and drafts a verdict naming the indicators it relied on — so an analyst confirms or overturns a judgement instead of opening four hundred near-identical mails.

Effort
Weeks of work
Skill level
Some technical skill
Organisation size
Mid-market
Value
Time saved, Risk reduced

Tools named for this

  • A mail parser that keeps the original headers and the raw source intact
  • A language model that returns its verdict together with the specific indicators it used
  • A link and attachment reputation or detonation service, run in isolation from the corporate network

What to check before you ship it in India

  • For service providers, intermediaries, data centres, body corporate and Government organisations, phishing attacks sit on the list of cyber security incidents that must be reported to CERT-In, and the direction of 28 April 2022 puts that window at six hours from noticing the incident. A triage queue reviewed the next morning has already spent it. Organisations outside those categories are not reached by the direction.
  • A reported message is somebody's mail. It routinely carries the reporter's own correspondence and personal data about third parties who never reported anything, and section 8(5) requires reasonable security safeguards over personal data in the fiduciary's control. The triage store is usually the least-guarded copy of it in the building.

Sources

Every claim on this page traces to one of these, on the date it was read.