ICES module
Integrated Cloud Email Security
Real-time detection, investigation, and response for every Microsoft 365 mailbox.
Detection models
Seven models, one explainable verdict.
Each message is scored against the specific threat categories that matter most to Microsoft 365 tenants.
Identity & relationship anomaly
Flags senders and recipients that break normal communication patterns for the mailbox.
Impersonation & spoofing
Catches domain and display-name spoofing before it reaches an inbox.
Financial fraud (BEC)
Surfaces payment-redirect and invoice-fraud patterns typical of business email compromise.
Credential phishing
Identifies credential-harvesting pages and login lures, including sandboxed URL analysis.
Content deception
Detects graymail and manipulative content designed to prompt risky action.
Malicious payload
Scans attachments for malware signatures, macros, embedded objects, and archive bombs.
Account compromise
Correlates signals that indicate a mailbox itself has already been taken over.
Beyond detection
The evidence and controls to act on a verdict.
Attachment sandboxing
YARA signatures, macro and embedded-object analysis, archive-bomb and path-traversal checks, plus OCR on rendered pages.
URL sandbox
Browser-based link inspection with screenshot evidence, captured before a user ever clicks.
Message actions
Delivered, quarantined, blocked, or bannered, applied automatically per verdict, with manual override by role.
Threat hunting
Metadata-only search across retained messages, investigate a pattern tenant-wide without opening every mailbox.
Email posture
Continuous baseline assessment of authentication and configuration, tied to Microsoft Secure Score.
AI incident briefs
Workers AI-generated context on each incident, so analysts spend less time reconstructing the story by hand.
Workflow
One operating rhythm, start to finish.
01
Detect
Trace messages, inspect detection models, and understand the evidence behind a verdict.
02
Protect
Strengthen posture and authentication with the same explainable signal set.
03
Respond
Collaborate on incidents, quarantine risky mail, and coordinate provider actions.