With security analysts pulled in many directions, they must be able to prioritize and invoke incident response on ransomware, business email compromise (BEC), malware infections, and credential-based theft emails. The key to this is the automation and streamlining of the incident response. PhishMe Triage™ has been updated with new features to help security analysts and incident response teams streamline their processes and secure administrative access.
Key Features this Release
- Tighter Integration – Authenticated API for integration across the incident response team
- Additional Security – Two-factor authentication for PhishMe Triage users
- More Accountability – Audit logs are generated for all users of PhishMe Triage
- Better Visibility – System status alerts can be distributed via syslog
The new API is designed to help PhishMe Triage interact with other systems across the incident response process. This authenticated API enables other systems to “talk” to PhishMe Triage to automate the process and get the right teams involved, faster. The fully documented REST API can be used to pull information from PhishMe Triage on emails, clusters, attachments, reporters, integrations, health stats and more. The API can be used in the preprocessing stage to notify malicious attachments at soon as they are reported. Join the conversation in the PhishMe Community PhishMe Triage API discussion to share ideas and code samples for building solutions using the API.
This release adds in an additional layer of security for PhishMe Triage users. Two-factor authentication can be turned when a user logs in to PhishMe Triage. End users will install a standard two-factor authentication app on their mobile device, and then simply scan a QR code to register their phone with PhishMe Triage. At log in, they will be prompted for code generated by the app. This makes authentication based upon “something you know”, the password, and “something you have”, the app. There is support Google Authenticator and other two-factor tools.
This release also introduces audit logging in PhishMe Triage. With the audit log, visibility about who did something in PhishMe Triage, what they did and when they did it is captured. The audit log tracks over 145 Event ID’s across PhishMe Triage. This enables the tracking of all of the actions users of PhishMe Triage. These logs can be viewed directly inside of PhishMe Triage, or exported to another tool for more analysis.
This release also extends syslog alerting with PhishMe Triage. With syslog enabled, PhishMe Triage can send out alerts to other systems. Syslog alerts can be used to share information like the cluster velocity, operational SLA alerts, platform health, ingestion health and triage recipe monitoring. This enables PhishMe Triage to share alerts across the entire incident response team.
If you have any questions, please email [email protected]. Full details on the release are available in PhishMe Community. To access it, simply log in to your PhishMe Triage appliance and then click the “Visit PhishMe Community” icon.
Don’t ever miss another threat – sign up for PhishMe® Threat Alerts today and receive updates on new and emerging phishing and malware threats, completely free.