Catcher

Overview

Case Detail

INC-20260511-0008

Invoice INV-44821 for April services

benignlowanalysis_completed

Triage

Risk
8.5%
Confidence
high
Action
close_as_benign
Status
analysis_completed
  • SPF/DKIM/DMARC passed
  • Known vendor domain
  • No suspicious URLs

Message

From
Contoso Billing <billing@contoso.example>
Sender domain
contoso.example
Reporter
maria.sales@example.test
Reply-To
billing@contoso.example
Return-Path
billing-bounces@contoso.example
Message ID
<m365-report-0008@example.test>

Signals

SPF
pass
DKIM
pass
DMARC
pass
Clickable URLs
0
Shorteners
0
Attachments
1
Attachment reputation
clean
Stego reviews
0
QR decoded
0
Containers
0
Lure theme
invoice_or_payment
Platforms
-
Objectives
-
URL enrichment
off
Domain enrichment
off
Redirects
0
Final mismatch
0
Browser forms
0/0
Threat intel
off
Intel matches
-

Pipeline

Tenant
tenant-dev
Evidence ID
EVID-20260511-0008
Queue job
43
Run ID
20260511_121001_0000_EVID-20260511-0008
Closed by
soc-analyst@example.test
Close reason
Legitimate vendor invoice from allowlisted sender.
Closure note
Legitimate vendor invoice from allowlisted sender.