SECOPS

Agentic Phishing Investigation & Case Builder

An autonomous agent picks up each reported phishing email, detonates links in a sandbox, enriches indicators via web research, decides quarantine and escalation actions.

CategorySecOps
Enginepaperclip
Difficultyadvanced
Triggerevent
Steps6
Setup~25 min

How it runs

The automated pipeline, trigger to output.

  • TriggerReported email lands in abuse mailboxGmailGmail
  • ActionAgent detonates links in sandbox sessionBrowserbase
  • ActionEnrich domains and sender via web researchPerplexityPerplexity
  • LogicAgent decides disposition and blocks if maliciousCloudflareCloudflare
  • ActionWrite narrated investigation caseNotionNotion
  • OutputEscalate high-severity findings for reviewPagerDutyPagerDuty

What it does

Replaces the rote analyst workflow with an agent that reasons over a single phishing report end to end. It detonates the URLs, researches the domains and sender reputation, weighs the evidence, and produces a written case file with a recommended disposition and the actions it took, so a human reviews conclusions instead of doing the legwork.

When to use it

When report volume is unpredictable and you want consistent, well-documented investigations that capture not just a verdict but the reasoning and supporting evidence behind it.

How it works

  1. 1A new report arrives in the monitored Gmail abuse mailbox and hands the agent the raw email.
  2. 2The agent detonates each link in an isolated Browserbase session and inspects the landing behavior.
  3. 3It enriches the domains and sender with live web research to gauge reputation and registration age.
  4. 4The agent decides the disposition, blocking malicious infrastructure at Cloudflare when warranted.
  5. 5It composes a narrated investigation case with evidence and recommendations into Notion.
  6. 6High-severity findings are escalated through PagerDuty for human confirmation.

Set it up

What you configure once, before turning it on.

  1. 1
    Connect GmailRead, draft, send, label.
  2. 2
    Connect BrowserbaseHeadless browsers, sessions, replays.
  3. 3
    Connect PerplexitySearch-grounded answers with citations.
  4. 4
    Connect CloudflareWorkers, Pages, R2, KV — the edge stack.
  5. 5
    Connect NotionPages, databases, comments.
  6. 6
    Connect PagerDutyIncidents, on-call, escalations.
  7. 7
    Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
  8. 8
    Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
  9. 9
    Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.

Run this workflow in your colony.

14-day trial. No DevOps. No Sales call. Provisioned in under a minute.