💣📧 Email Threat AI
✉️ Email Threat AI — Powered by GEODI Discovery
Email Threat AI is an advanced module of GEODI Discovery and GEODI Q that automatically analyzes and classifies incoming emails using AI-based recognizers. It helps organizations detect and respond to suspicious, harmful, or unwanted emails in real time — without manual effort.
✅ Prerequisites
To use Email Threat AI, the following components must be in place:
GEODI Q must be licensed and active
GEODI Discovery must be configured for email sources
The solution is available via DECE-STORE with ready-to-use packages
Email sources (e.g., Microsoft 365 or Gmail) should be accessible via supported protocols (IMAP or Graph API)
🔍 What It Does
Email Threat AI classifies emails into the following categories:
PHISHING – Deceptive messages designed to steal credentials or mislead users
THREAT – Emails containing hostile, coercive, or alarming language
MALICIOUS – Emails with harmful attachments, links, or behaviors
ADVERTISEMENT – Promotional or irrelevant messages, often sent in bulk
AI recognizers analyze:
The email body and tone
Links and embedded URLs
Attachments (PDF, DOCX, etc.)
Sender metadata and domain trust
🧩 Integration with PII/PCI Discovery
Email Threat AI can be run as a standalone discovery or as part of a broader email discovery project. For example, you can combine threat detection with:
PII (Personally Identifiable Information) discovery
PCI (Payment Card Industry) data detection
Policy violation checks, such as data exfiltration or regulatory non-compliance
💡 GEODI comes with a built-in EmailThreatAI recognizer.
You can simply activate GEODI Q in the project and add this recognizer to your Discovery project alongside other recognizers like PII, PCI, or custom patterns. This allows unified classification and risk analysis in a single run.
This flexibility makes Email Threat AI ideal for both security operations and compliance audits.
📊 Real-Time Threat Dashboard
GEODI provides a visual Threat Intelligence Panel where you can:
View total threat counts by category
Monitor trends over time (daily, weekly, monthly)
Filter threats by user, domain, or classification
Export threat data for reporting or compliance audits
This dashboard supports proactive monitoring by IT and security teams. Only ACC.Discovery group members access this panel.
🔁 Automated Workflow and Notifications
GEODI includes an automated workflow to notify relevant teams:
Each time a threatening email is detected, GEODI:
Triggers a predefined workflow
Sends an alert email to the
ACC.Discoverymail groupLogs all details including the detection timestamp and threat classification
💡 Setup Tip:
Just create a mail group named
ACC.Discoveryand add your security personnel to it. The rest is automatic.
Optional integrations:
SIEM platforms (e.g., Splunk, QRadar)
Ticketing systems (e.g., Jira, ServiceNow)
Incident response tools
⚙️ Deployment and Setup
Deployment is simple and fully managed via DECE-STORE:
One-click install of the Email Threat AI module
Supports shared and individual mailboxes
Compatible with Microsoft 365 and Google Workspace (IMAP / Graph API)
Background operation – no user interaction required
Ready-to-use recognizers and workflows are included
🎯 Why Use Email Threat AI?
✅ Detect phishing and malicious emails before they cause harm
✅ Gain insights into your organization's email threat landscape
✅ Automate security workflows and reduce response time
✅ Ensure compliance with regulations (KVKK, GDPR, ISO 27001)
✅ Improve visibility for SOC and IT teams