Default Behaviour of Incident Responder

πŸ€– Analysis

  1. An employee reports a suspicious email using the Keepnet Reporter Button or Native Microsoft Report button

  2. Keepnet analysis the reported email for malicious content in seconds using 5+ integrations simultaneously

  3. Keepnet automatically shares the analysis result with the employee via email

Incident Responder β€” employee reports email, analysis result sent.
Incident Responder β€” employee reports email, analysis result sent.

πŸ”Ž Investigate

  1. When analysis result is β€œMalicious”, Keepnet starts an automatic investigation to find all instances of the malicious content

  2. Once investigation is complete, Keepnet System Admins receive Investigation Report

  3. Keepnet System Admin can then log into Keepnet and delete all instances of malicious emails in a few clicks

Incident Responder β€” investigation report, delete malicious instances.
Incident Responder β€” investigation report, delete malicious instances.

Last updated