All automations

Email Security + n8n

SOCFlow Phishing Email Triage

An offline-first phishing triage workflow for SOC L1 analysis. It accepts a pasted email or uploaded EML artifact, extracts sender/header/link/attachment evidence, checks authentication results, calculates an explainable risk score, and returns a downloadable HTML evidence pack without browsing suspicious links or taking automatic containment action.

6Workflow nodes
HTMLEvidence pack
100Max risk score

SYSTEM ARCHITECTURE

From raw signal to accountable decision.

01 / Submit

An analyst submits a suspicious email through a local n8n form.

02 / Extract

The workflow parses headers, body text, links, domains, IPs, and attachment names.

03 / Score

Deterministic rules calculate phishing, BEC, credential, URL, and attachment risk.

04 / Report

n8n returns a structured evidence pack with analyst recommendations and limitations.

PROCESS

01Submit02Parse03Extract04Score05Report06Approve

CAPABILITIES

What the automation delivers.

EML and pasted-header intake

SPF/DKIM/DMARC parsing

URL and domain extraction

Attachment-name risk checks

Explainable offline scoring

Downloadable HTML evidence pack

SAMPLE OUTPUT

Fake Microsoft credential reset email

SEVERITYCritical

RISK SCORE100 / 100

RECOMMENDATIONLikely credential phishing

Webhook endpoint: /form/socflow-phishing-triage