// osprey sentry / sukčiavimo laiškų analizatorius

Sukčiavimo laiškų analizatorius

Pateikite įtartiną laišką ir gaukite analitiko lygio išvadą — siuntėjo autentiškumą, nuorodų vientisumą, kalbinę manipuliaciją ir naudingosios apkrovos riziką — sujungtą į vieną balą, kartu su jau paruoštais atsako veiksmais.

// the automated inspection engine

Six phases, run in order — cheapest first

Every submission passes through a sequential, non-destructive pipeline. The order is deliberate: it resolves obvious spam and legitimate traffic before spending heavy compute — like dynamic sandboxing — on anything.

01

Ingestion & structural parsing

A raw .eml or .msg is split into its foundational elements — transport headers, plain-text and HTML bodies, and binary attachments. Parsing is passive: nothing is rendered, nothing is executed.

02

Authentication verification

SPF, DKIM and DMARC results are read from the receiving gateway's headers, then checked for strict domain alignment — does the From domain actually match the domain these protocols authorised?

03

Link extraction & sanitization

Every hyperlink is extracted and de-obfuscated, shorteners are resolved to their true destination, and the visible display text is compared against the real href target.

04

Natural-language & behavioural analysis

An NLP pass reads the text for behavioural anomalies: urgent calls to action, credential-verification requests, financial manipulation themes and pretexting.

05

Attachment reputation & sandboxing

Attachments are hashed (SHA-256) and statically inspected for type abuse. Only files that fail static inspection are routed to the isolated sandbox — the expensive step runs last, and only when warranted.

06

Risk scoring & automated response

Every indicator rolls into a single 0–100 score. High-risk verdicts trigger SOAR workflows: tenant-wide quarantine, blocklist updates and SOC notification.

// the risk scoring model

Weighted indicators, not a checklist

Individual indicators are weighted into one actionable metric, so analysts never burn time on low-level spam and targeted credential harvesting gets attention immediately.

Analysis categoryKey indicators checkedWeightWhy it matters
Link integrityTyposquatting, homoglyph/IDN attacks, display-text vs href mismatch, redirect chains30%CriticalDirect indicator of intent to steal credentials or trigger a drive-by download.
Cryptographic identitySPF / DKIM / DMARC failures, domain alignment mismatches, Reply-To diversion25%HighThe strongest indicator that an email is actively impersonating a known brand.
Network & reputationBrand-new domain age, no DNS/MX, disposable providers, high-abuse TLDs25%HighAttackers spin up cheap, disposable domains for temporary campaigns.
Behavioural NLPFinancial keywords, high-pressure urgency, secrecy cues, spoofed authority10%Low-MediumFlags psychological manipulation, but is deliberately weighted low — it needs a technical indicator to corroborate it, or legitimate urgent mail becomes a false positive.
Payload & attachmentsDouble extensions (invoice.pdf.exe), macro-capable documents, HTML smuggling, archives10%HighAttempts to bypass OS file-type detection to deliver an executable payload.
// submit a message

Analyse a suspicious email now

The verdict, score and authentication matrix are free. Register a company account to unlock the full report — link inspection, sender intelligence, attachment analysis, the safe visual preview and the response plan.

Drop an .eml or .msg file here, or click to browseForwarded emails lose their original headers — export or drag the message itself so SPF, DKIM and DMARC can be verified. Up to 25 MB.
🔒 Sent over TLS · parsed passively · never rendered or executed
// the analyst command center

Built to cut through noise, not add to it

The front end has one job: minimise mean time to resolution by grouping identical threats together. Every submission you make is fingerprinted into a campaign, so the queue counts unique threats — not inbox volume.

Sign in above and your live submission queue — total vs unique, verdict split and incident count — appears here.

Phishing Analyzer report dashboard: total vs unique submissions, verdict breakdown, campaign donut and submissions-by-priority chart
The analyst report view — total vs unique submissions, verdict split, campaign distribution and submissions by priority over the last 30 days.

What the report looks like

The power of deduplication

The dashboard aggregates total submissions against unique submissions. If 100 employees report the same corporate-wide campaign, the analyst sees a single card in their queue — and resolving that one card resolves all 100 reports simultaneously.

Authentication visual matrix

A clean, colour-coded grid of SPF, DKIM and DMARC status. An email claiming to be from a major SaaS platform that fails domain alignment draws the eye instantly.

Side-by-side link inspection

User-facing text sits directly beside the underlying href. When the text says Sign in to Microsoft but the target is auth-microsoft-update.xyz, the mismatch is highlighted in red.

Safe visual preview

A headless-browser screenshot of the email body lets analysts see exactly what the user saw — with scripts disabled and every outbound request blocked, so no tracking pixel ever tells the attacker you looked.

// privacy & handling

Submitted messages are handled as evidence

Never executed

Bodies are parsed as inert text and attachments are hashed, never run. The optional visual preview renders with JavaScript disabled and all outbound requests blocked.

We don't touch attacker infrastructure

Only known URL shorteners are resolved, and never into private address space. We don't fetch arbitrary links — that would tip off the attacker and turn this into an open proxy.

Stored to your account only

Reports are stored against your company account so the campaign queue can deduplicate across your reporters. Nobody else can retrieve them, and anonymous submissions never enter a tenant's queue.

Your responsibility to submit lawfully

Emails contain personal data. You confirm you're authorised to submit them; handling follows GDPR principles of minimisation and purpose limitation.

// saugome tai, kas svarbiausia

Perimkite savo perimetro kontrolę

Užsiregistruokite CYBORA GRC ir HybridSOC platformos bandomajai demonstracijai. Viena komanda, atsakinga už visą jūsų kibernetinio saugumo ciklą.