Complete AI Training
Sign inGet my AI kit

Your job's AI kit

Get your AI kit

Tell us who you are and what you do. We show you your kit right away and email you the link: skills, prompts, AI agents, MCP servers and courses for your job.

500+ jobs ready, and we make a kit for any other job. No payment needed to look.

Share

AI agent for cybersecurity analysts

Phishing Report Triage Agent

Every reported email classified, and malicious copies found and contained

Phishing Report Triage Agent: what goes in, what the agent does and what you get

What it does

Staff report suspicious emails every day, and real attacks wait in the queue behind harmless newsletters. This agent reads each report and checks the sender, links and attachments against threat intelligence and a safe sandbox. It decides whether the email is malicious, spam or safe. If the verdict is unclear, it runs deeper checks, such as opening the attachment in the sandbox or checking domain age, before deciding. For malicious mail it searches all mailboxes for copies and checks whether anyone clicked. It drafts the removal of copies and a reply to the reporter. You approve removing emails and resetting accounts. Edge case: a link that looks clean today but whose domain was registered yesterday is treated as suspicious.

How it works

Follow the arrows from top to bottom. The orange dashed arrow is the loop: when a check fails, the agent goes back and tries again.

Start and resultWhat it doesA check on its own workWaits for your OKGoes back and retries
Yes, continueApprovedNo 1 STARTS WHEN User reports an email 2 USES A TOOL Extract sender, links and attachments 3 USES A TOOL Check indicators against threat intelligence 4 CHECKS THE RESULT Is the verdict clear? If not: open links and attachments in the sandbox andcheck domain age. Back to step 3. 5 USES A TOOL Search all mailboxes for copies and click logs 6 DOES Draft removal plan and reply to reporter 7 YOU APPROVE Analyst approves removal and any account resets 8 RESULT Case closed with verdict recorded
Read the steps as a list
  1. User reports an email
  2. Extract sender, links and attachments
  3. Check indicators against threat intelligence
  4. Is the verdict clear?If not: open links and attachments in the sandbox and check domain age. Back to step 3.
  5. Search all mailboxes for copies and click logs
  6. Draft removal plan and reply to reporter
  7. Analyst approves removal and any account resetsThe agent waits here for your OK.
  8. Case closed with verdict recorded

How it decides

It weighs sender reputation, link and attachment results and domain age. A malicious verdict needs at least one confirmed bad indicator.

  • Treat domains under 30 days old as suspicious
  • Malicious requires a confirmed bad link, file or sender
  • Check sign-ins for anyone who clicked a malicious link

Make it yours

Every agent is a starting point. You choose these settings for your own situation.

  • Domain age that counts as suspicious
  • Threat intelligence sources
  • Reply template for reporters
  • Auto-close rules for marketing mail

What keeps you in control

It always asks you first

  • Removing emails from mailboxes
  • Resetting passwords or blocking accounts

Hard limits

  • Never removes mail or resets accounts without approval
  • Opens attachments only in the sandbox

It stops when

  • Done: verdict made and containment approved
  • Stop: email sample is missing or corrupted

Set it up

We guide you through the set-up, step by step

Members get the full set-up guide for this agent. No technical skills needed: you copy, paste and upload.

10 minto set it up in your AI
5 AIsChatGPT, Claude, Copilot, Gemini, Grok
  • One set of instructions to paste into your AI, with the clicks for ChatGPT, Claude, Microsoft 365 Copilot, Gemini and Grok
  • The agent then walks you through connecting your own data, one source at a time
  • A downloadable copy with the flow chart, the rules and the full guide
Get access to this agent

An example run

What happensOn September 9 a staff member at Northgate Builders reported a fake invoice email. No known bad indicators matched, so the verdict check came back unclear. In the sandbox the attachment opened a credential page on a 2-day-old domain. The agent found 37 copies and 2 clicks. It drafted removal plus password resets for the 2 users, and the security analyst approved both.

More agents for cybersecurity analysts