Phishing email analysis powered by Recorded Future
Build a workflow triggered by a reported phishing email. Extract the sender domain, URLs, and attachment hashes, and check for leaked credentials. Enrich each via Recorded Future, compile the risk picture, and email the results to the analyst. If the verdict is malicious, create a case in the case-management system. Handle missing artifacts, API rate limits, and retries. Output the consolidated analysis and any case created.
What this prompt builds
Analyze a phishing email's domain, URLs, leaked creds, and attachments with Recorded Future intel.
The problem
Phishing triage without good threat intel produces low-confidence verdicts, so analysts hesitate and response slows. Manually enriching every artifact in Recorded Future is repetitive.
Solution and impact
This workflow enriches a phishing email's sender domain, URLs, leaked credentials, and attachments with Recorded Future and emails the results, optionally creating a case. Analysts get an intel-backed verdict and a documented case with minimal effort.