Data & Integrations
Email Security
Phishing and malicious attachments, analysed.
Available as a standalone module · Add to my package42Sources
3.2MEvents today
19 / 19Healthy
- Phishing indicatorsActive
- Attachment and URL checksActive
- Sender reputationActive
- Correlation with endpoint eventsActive
What it does
Email events are analysed for phishing indicators, suspicious senders and malicious attachments, and correlated with endpoint activity.
Phishing indicators
Attachment and URL checks
Sender reputation
Correlation with endpoint events
How it worksin three steps.
Connect
Add a source with syslog, an agent, an API token or a file upload.
Normalise
Parsers detect the format and map every event to one schema.
Route
Events flow to detection, search, reports and your SOAR tools.
Works best withthese modules.
See all 30 modules
Investigation & Forensics
Log Explorer
Search billions of events in milliseconds.
Learn more Threat IntelligenceDetection Rules
Manage SIGMA and YARA rules, or write your own.
Learn more Automation & AISOC Automation
Visual flows from detection to response.
Learn moreAlso in Data & Integrations
Ready to see it on your own data?
A 30-minute walkthrough with an engineer, tailored to your environment.