Cofense Unveils Automated Phishing Detection and Response Capability
Cofense Triage and Vision customers will be able to leverage the network effect of phishing intelligence curated from millions of suspicious emails reported into our solutions
Cofense, the leading provider of phishing detection and response (PDR) solutions, announced new product innovations to Cofense Vision. Most notably, the addition of an Auto Quarantine feature that identifies and automatically removes malicious emails from recipients’ inboxes – often before users see or have a chance to open them, based on our knowledge of similar threats in other customer environments. This high degree of automation significantly reduces the time to identify and resolve attacks, provides protection from threats that bypass Secure Email Gateways (SEGs) every day, and lessens a security analyst’s time spent hunting malicious email. Auto Quarantine is powered by the Cofense Intelligence network of Cofense researchers, the Phishing Defense Center (PDC) team of analysts, and millions of people around the world identifying and reporting suspected phish.
The Cofense team closely monitors the threat landscape and is able to leverage a global network of over 25 million human sensors identifying and reporting on suspicious emails, and a team of advanced researchers and intelligence analysts to create an unparalleled view of threats happening in real time around the world. The moment a threat is identified, Cofense analysts generate an Indicator of Compromise (IOC) tuned to stopping that threat. With Vision’s Auto Quarantine feature, these IOCs are used to identify malicious emails that have bypassed the SEG seconds after they are received. When a match is found, the email is auto quarantined where it can then be examined and if appropriate, removed permanently. Current Cofense Vision users are observing several such threats as being automatically addressed every day, thus significantly reducing the window of vulnerability to active email-borne threats like ransomware, business email compromise (BEC), malware attacks, and credential theft.
Cofense Vision with Auto Quarantine Proven Effective in Enterprise Organizations
Fortune 500 Retail Organization:
A large retail customer was an early adopter of Cofense Vision with Auto Quarantine. The account team provided an email to the customer with a recently identified public malicious phishing link. The email completely bypassed all of the existing email security controls. But within seconds, and before the recipient could open the email, Vision identified the email as a threat and auto quarantined it. This happened without any human intervention.
Large, Full-service Mortgage Provider:
This enterprise organization deployed Vision with the new Auto Quarantine feature across its organization. During the first week, Vision identified six separate phishing campaigns. Each of these campaigns contained approximately 500 phishing emails that had bypassed existing email security technology and made it to recipient inboxes. The Vision Auto Quarantine functionality immediately quarantined the thousands of emails without analyst interaction and before a recipient could open the email, quickly and effectively reducing risk to the organization. Prior to Vision, the team did not have visibility into the extent of phishing campaigns nor any systematic way to identify and remove them.
Global Construction Company:
When this global construction company enabled Auto Quarantine, they saw an immediate impact. A phishing campaign disguised as a Microsoft Teams invite to a holiday party appeared shortly after Auto Quarantine was configured. The email was immediately identified as a phishing campaign and over 200 emails were auto quarantined. After the initial detection, the company continued to be targeted with the same phishing campaign and the auto quarantine functionality in Vision has continued to detect and remove several dozen more attacks.
“Phishing threats are human-developed, which is why Cofense is helping organizations ‘out-human’ the phishing threat. By continuously updating our solutions with capabilities to remove real-world threats before anyone in the organization even sees them, Cofense is greatly reducing the risk of a phishing attack,” says Aaron Higbee, Co-Founder and CTO of Cofense. “With the newest version of Cofense Vision, organizations can immediately operationalize Cofense’s indicators of compromise and automatically remove malicious email from an environment even before a team member tags them as suspicious. Customers are quickly adopting Auto Quarantine for its effectiveness in stopping threats that bypass SEGs, and for delivering immense productivity gains for SOC and IR teams.”