Phishing report triage
Turns an employee phishing report into a verified verdict and a block decision the same day.
Tools
Microsoft Defender for Office 365, Proofpoint, Microsoft Sentinel, Jira Service Management
Outcomes
Verdict within 30 minutes of the report • One case per incident, not per reporter • Confirmed phishing blocked company-wide
Documentation
Instruction-ready detail below
Reports arrive as forwarded messages with no context, so the analyst has to re-derive the sender, the real link target, and whether anyone else received the same file. Six people report one phish and it gets worked six times.
The workflow starts at the report. It pulls the original message and its headers from the report mailbox, checks whether the mail gateway delivered or already blocked it, and looks for the same indicators in the previous 30 days. It sets one verdict from a fixed set: confirmed phishing, credential harvest, benign, or cannot tell. The evidence behind that verdict is attached to the case rather than described in it.
From there the boring parts happen the same way every time. One case is opened for the incident, the impacted recipients are listed, the indicators go to the block list, and a human approves the company-wide block and any message to staff. A report that turns out to be a real account takeover moves to incident triage instead of closing. A human still approves every block, every purge, and every outbound notification.