Phishing email analysis powered by Recorded Future

Starting promptUse this prompt as a starting point to build your workflow.

Build a workflow triggered by a reported phishing email. Extract the sender domain, URLs, and attachment hashes, and check for leaked credentials. Enrich each via Recorded Future, compile the risk picture, and email the results to the analyst. If the verdict is malicious, create a case in the case-management system. Handle missing artifacts, API rate limits, and retries. Output the consolidated analysis and any case created.

New to Tines?Sign up free for Tines 3B Explore Edition

What this prompt builds

Analyze a phishing email's domain, URLs, leaked creds, and attachments with Recorded Future intel.

The problem

Phishing triage without good threat intel produces low-confidence verdicts, so analysts hesitate and response slows. Manually enriching every artifact in Recorded Future is repetitive.

Solution and impact

This workflow enriches a phishing email's sender domain, URLs, leaked credentials, and attachments with Recorded Future and emails the results, optionally creating a case. Analysts get an intel-backed verdict and a documented case with minimal effort.