Suspicious Email Triage with EDR Correlation
Multi-tool email triage that cross-references threat intel with CrowdStrike endpoint detections.
Overview
A tier-2 triage playbook for suspicious emails that goes beyond URL and attachment scanning. It cross-references the findings with CrowdStrike Falcon endpoint detections to see if the indicators have already been seen on your network, then creates a Jira ticket with the full investigative timeline.
Who this is for: Tier-2 and tier-3 SOC analysts investigating potentially active phishing attacks
Why automate this
The real question for a suspicious email isn't 'is this URL malicious?'. It's 'have any of our endpoints already reached out to this URL?'. This playbook answers that by correlating email IOCs with CrowdStrike telemetry, turning passive email triage into active breach hunting.
How it works
- 01
Retrieve the suspicious email metadata and content
- 02
Check sender reputation with EmailRep
- 03
Scan all URLs with URLScan.io
- 04
Hash and analyze attachments with VirusTotal
- 05
Query CrowdStrike Falcon for endpoint detections matching the IOCs
- 06
Correlate email indicators with endpoint activity
- 07
Build an investigative timeline with all findings
- 08
Create a Jira ticket with the full triage report
- 09
Notify the security team in Slack
Impact
Detects active compromise triggered by the suspicious email
Correlates email and endpoint signals in one flow
Creates a single investigative artifact in Jira
Massively cuts investigation time for tier-2 analysts
Related playbooks
Keep automating
Multi-Source Phishing Email Analysis
Analyze phishing emails with EmailRep, URLScan, and VirusTotal to produce a comprehensive threat report.
Outlook Phishing Detection with VirusTotal
Scan every inbound Outlook email for malicious URLs and attachments, delete threats, and notify Slack.
Gmail Phishing Detection with VirusTotal
Scan incoming Gmail messages for malicious links and attachments, delete threats, and alert security.
Bring this playbook into your SOC
See Deployer Workflows in action with a live walkthrough of this playbook. We'll show you how to connect your SIEM, EDR, and ticketing tools in under 15 minutes.