TriageMTTR

Phishing Report Verdict

Pulls the reported message and headers, checks the mail gateway, and returns a verdict with the evidence attached.

Part of Phishing report triage

Tools

Microsoft Defender for Office 365, Microsoft Sentinel, Slack

Outcomes

Verdict within 30 minutes • Evidence attached to one case • Duplicate reports merged

Documentation

Instruction-ready detail below

When <in:email>a phishing report</in:email> lands, pull the original message and headers, check whether the gateway delivered it, and <slack>post</slack> a verdict of phish, credential harvest or benign with the evidence.

Instruction file

When <in:email>a phishing report</in:email> lands, pull the original message and headers, check whether the gateway delivered it, and <slack>post</slack> a verdict of phish, credential harvest or benign with the evidence.

Setup requirements

Tools

Microsoft Defender for Office 365, Microsoft Sentinel, Slack

Trigger

When an employee reports a suspicious email

Setup time

20 minutes

Download

Start with one instruction file.

Download the app and begin with drafts and checklists before you write anything back.

  • •Plain-language instructions
  • •Runs on your machine
  • •Works with your existing setup
  • •Reviewable activity history
Download