IntegralDefense / ACE

Analysis Correlation Engine
Apache License 2.0
25 stars 10 forks source link

parse phishme reports #168

Closed unixfreak0037 closed 5 years ago

unixfreak0037 commented 5 years ago

When users submit phish reports via phishme, we pick that up as inbound emails and process them as normal emails.

PhishMe is sending various bits of information in the email which we can pull out and add to the analysis, including the original emails headers, but also the message_id, which we can pull out and add to the analysis so that we get the original email (which should be archived if you have archiving on.)

KarmaPenny commented 5 years ago

got an example phishme report I could look at?

unixfreak0037 commented 5 years ago

shared internally