Popular Customisations
Some customers like to customise the default behaviour of the Incident Responder and the relevant Notification Templates associated with the default workflow. Below are some popular customisation our customers request and how to achieve each one:
Customise Notifications
Customers can fully customise notifications employees and system admins receive when they report an email for Analysis Results & Investigation Updates. You can view the default notification template here
To make customisations, please go to:
Company > Company Settings > Notification Templates
Filter Category by "Incident Responder"
Click on the 3 dots to the right then select "Duplicate" to be able to edit
Make all the customisations you would like, including:
Email Delivery (select Direct Email Creation if setup)
Subject Line
From Name
From Email Address (must be keepnetlabs.com unless you have selected Direct Email Creation or setup your own SMTP)
Body of the Email
Once you're happy with your edits, Save the template
Set this template as default by click on the 3 dots and selecting "Make Default" - don't forget this step!

Please note: If you have not purchased the Incident Responder, you will not be able to see Notification Templates for the Incident Responder module.
Auto-delete Malicious Emails
As you will have seen, the Default Behaviour of Incident Responder automatically analyses reported email and then automatically runs an investigation for all emails which are found malicious. To take this one step further, you can automate the deletion of all instances of malicious emails.
This is not enabled by default, allowing system admins to decide whether emails should be deleted - especially in rare cases where a safe email may be incorrectly flagged as malicious.
To set this up, please follow the below instructions:
Incident Responder > Playbook
Create a new Playbook by click on the blue +NEW button
Rule Info: Name the playbook and add a description
Conditions: Set to From > exists (this will cover all reported emails)
Actions: Create a new workflow
Select "Analyse" from the drop down
Select all Integrations (if you don't have any setup, please follow these steps)
Tick the box - "Investigate according to analyze results"
Select Sources > Select the Mail Integration you have setup
Actions > Delete Email
SAVE
Top Tip: if you have multiple Playbooks running, set the priority for this one as Very High to ensure this rule will supersede the other rules you have in place
Last updated
Was this helpful?