💣📧 Email Threat AI

💣📧 Email Threat AI

 


✉️ Email Threat AI — Powered by GEODI Discovery

Email Threat AI is an advanced module of GEODI Discovery and GEODI Q that automatically analyzes and classifies incoming emails using AI-based recognizers. It helps organizations detect and respond to suspicious, harmful, or unwanted emails in real time — without manual effort.


✅ Prerequisites

To use Email Threat AI, the following components must be in place:

  • GEODI Q must be licensed and active

  • GEODI Discovery must be configured for email sources

  • The solution is available via DECE-STORE with ready-to-use packages

  • Email sources (e.g., Microsoft 365 or Gmail) should be accessible via supported protocols (IMAP or Graph API)


🔍 What It Does

Email Threat AI classifies emails into the following categories:

  • PHISHING – Deceptive messages designed to steal credentials or mislead users

  • THREAT – Emails containing hostile, coercive, or alarming language

  • MALICIOUS – Emails with harmful attachments, links, or behaviors

  • ADVERTISEMENT – Promotional or irrelevant messages, often sent in bulk

AI recognizers analyze:

  • The email body and tone

  • Links and embedded URLs

  • Attachments (PDF, DOCX, etc.)

  • Sender metadata and domain trust


🧩 Integration with PII/PCI Discovery

Email Threat AI can be run as a standalone discovery or as part of a broader email discovery project. For example, you can combine threat detection with:

  • PII (Personally Identifiable Information) discovery

  • PCI (Payment Card Industry) data detection

  • Policy violation checks, such as data exfiltration or regulatory non-compliance

💡 GEODI comes with a built-in EmailThreatAI recognizer.
You can simply activate GEODI Q in the project and add this recognizer to your Discovery project alongside other recognizers like PII, PCI, or custom patterns. This allows unified classification and risk analysis in a single run.

This flexibility makes Email Threat AI ideal for both security operations and compliance audits.


📊 Real-Time Threat Dashboard

GEODI provides a visual Threat Intelligence Panel where you can:

  • View total threat counts by category

  • Monitor trends over time (daily, weekly, monthly)

  • Filter threats by user, domain, or classification

  • Export threat data for reporting or compliance audits

This dashboard supports proactive monitoring by IT and security teams. Only ACC.Discovery group members access this panel.


🔁 Automated Workflow and Notifications

GEODI includes an automated workflow to notify relevant teams:

  • Each time a threatening email is detected, GEODI:

    • Triggers a predefined workflow

    • Sends an alert email to the ACC.Discovery mail group

    • Logs all details including the detection timestamp and threat classification

💡 Setup Tip:

Just create a mail group named ACC.Discovery and add your security personnel to it. The rest is automatic.

Optional integrations:

  • SIEM platforms (e.g., Splunk, QRadar)

  • Ticketing systems (e.g., Jira, ServiceNow)

  • Incident response tools


⚙️ Deployment and Setup

Deployment is simple and fully managed via DECE-STORE:

  • One-click install of the Email Threat AI module

  • Supports shared and individual mailboxes

  • Compatible with Microsoft 365 and Google Workspace (IMAP / Graph API)

  • Background operation – no user interaction required

  • Ready-to-use recognizers and workflows are included


🎯 Why Use Email Threat AI?

  • ✅ Detect phishing and malicious emails before they cause harm

  • ✅ Gain insights into your organization's email threat landscape

  • ✅ Automate security workflows and reduce response time

  • ✅ Ensure compliance with regulations (KVKK, GDPR, ISO 27001)

  • ✅ Improve visibility for SOC and IT teams


 

image-20250709-063819.png