Building a Copilot agent to catch phishing that slips past our filters worth it?
We’ve got the usual stack in place (Defender for O365, SPF/DKIM/DMARC, Purview labels, user awareness training) but obviously nothing catches 100% of it. I’m thinking about building a Copilot/Power Automate agent that reviews flagged or borderline mail and…
We’ve got the usual stack in place (Defender for O365, SPF/DKIM/DMARC, Purview labels, user awareness training) but obviously nothing catches 100% of it. I’m thinking about building a Copilot/Power Automate agent that reviews flagged or borderline mail and scores it on classic phishing signals like urgency/pressure language, sender-domain mismatches, spoofed display names, weird links, etc. Not trying to replace the SEG, more like a second-opinion layer for the stuff that already got through or landed in a gray zone. Curious if anyone’s actually done this and whether it’s worth the effort vs. just tuning what we have. (Sick of also telling people if you don’t expect an email I would not trust it)
Collected discussion
No need to reinvent the wheel here. Get Abnormal and call it a day. They figured this out already. Pairs extremely well with Defender and does more than just email.
It's alright. We get a lot of false positives with Abnormal which is really annoying. They flag the simplist of things sometimes.
I find this surprising. I don't think I've seen more than one false positive over a year from Abnormal. It's been a huge surprise how accurate it is given what I'm used to with a traditional SEG.
Hell yes!
They have a pretty bad "known sender/historical sender" tracking. I've been told it's mostly based on your users sending to that person "recently". That's where some of my false positives are. Our false positives have dropped down to about 1 legitimate conversation a day at this point and we have at least 300k inbound emails a day. With that said, they haven't outright missed much. Probably bless than 1 outright per quarter, even if that much.
This comment was deleted.