Triage
- Risk
- 87.5%
- Confidence
- high
- Action
- quarantine_or_block_sender
- Status
- analysis_completed
- Header domain mismatch
- Credential-harvest language
- Lookalike sender domain
Message
- From
- IT Helpdesk <it-support@micros0ft-login.example>
- Sender domain
- micros0ft-login.example
- Reporter
- alex.reporter@example.test
- Reply-To
- helpdesk-reset@example.net
- Return-Path
- bounce@bulk-sender.example
- Message ID
- <m365-report-0007@example.test>
Signals
- SPF
- fail
- DKIM
- none
- DMARC
- fail
- Clickable URLs
- 3
- Shorteners
- 1
- Attachments
- 1
- Attachment reputation
- suspicious
- Stego reviews
- 0
- QR decoded
- 1
- Containers
- 0
- Lure theme
- credential_or_mfa_collection
- Platforms
- forms_or_survey, security_wrapper, url_shortener
- Objectives
- credentials, mfa or otp
- URL enrichment
- completed_with_warnings
- Domain enrichment
- completed_with_warnings
- Redirects
- 2
- Final mismatch
- 1
- Browser forms
- 1/1
- Threat intel
- completed
- Intel matches
- 2
Pipeline
- Tenant
- tenant-dev
- Evidence ID
- EVID-20260511-0007
- Queue job
- 42
- Run ID
- 20260511_115512_0000_EVID-20260511-0007
- Closed by
- -
- Close reason
- -
- Closure note
- -