Email is the most common way in. The Security Suite's email security inspects inbound (and optionally internal and outbound) mail for phishing, malware, and business-email-compromise, and feeds what it finds to the Managed SOC.
What it catches
| Threat | How it's handled |
|---|---|
| Phishing | URL and content analysis, brand-impersonation and look-alike-domain detection. |
| Malware | Attachment scanning and sandbox detonation of suspicious files. |
| Business email compromise (BEC) | Detects display-name spoofing, payment-change and wire-fraud patterns. |
| Malicious links | Time-of-click URL rewriting so a link weaponized after delivery is still blocked. |
How it connects
Email security integrates with Microsoft 365 and Google Workspace via API — no MX change required for detection. You choose whether it monitors (detects and alerts) or enforces (quarantines and blocks), per policy.
Quarantine & user reporting
Set the quarantine policy
In Security Suite → Email, decide what gets quarantined outright versus tagged with a warning banner, and who can release messages.
Give users a report button
Deploy the one-click Report phishing button in Outlook/Gmail so users can flag suspicious mail; reports become SOC signals.
Review releases
Admins (or the SOC) review quarantine and release false positives. Patterns from releases tune future filtering.
Identity-aware defense
Email security works with identity protection: a phishing click that leads to a risky sign-in correlates into one story, so the SOC sees the whole attack chain — the lure, the click, and the account takeover attempt — rather than three disconnected alerts. That stitching is cross-vendor attack-chain reconstruction at work: mail, identity, and endpoint events land on a single timeline.
Tip
Turn on internal mail scanning where your platform supports it. Once one account is compromised, the most convincing phishing comes from inside — from a real, trusted colleague's mailbox.
