An analyst submits a suspicious email through a local n8n form.
Email Security + n8n
SOCFlow Phishing Email Triage
An offline-first phishing triage workflow for SOC L1 analysis. It accepts a pasted email or uploaded EML artifact, extracts sender/header/link/attachment evidence, checks authentication results, calculates an explainable risk score, and returns a downloadable HTML evidence pack without browsing suspicious links or taking automatic containment action.
SYSTEM ARCHITECTURE
From raw signal to accountable decision.
The workflow parses headers, body text, links, domains, IPs, and attachment names.
Deterministic rules calculate phishing, BEC, credential, URL, and attachment risk.
n8n returns a structured evidence pack with analyst recommendations and limitations.
PROCESS
CAPABILITIES
What the automation delivers.
EML and pasted-header intake
SPF/DKIM/DMARC parsing
URL and domain extraction
Attachment-name risk checks
Explainable offline scoring
Downloadable HTML evidence pack
SAMPLE OUTPUT
Fake Microsoft credential reset email
SEVERITYCritical
RISK SCORE100 / 100
RECOMMENDATIONLikely credential phishing
Webhook endpoint: /form/socflow-phishing-triage