User wants to use the CrowdStrike M365 Email Phishing plugin within a SOAR automation to perform initial triage of phishing emails. This includes checking against VirusTotal, performing display name checks for VIP staff, and then routing potentially suspicious emails to a Jira queue. They are asking if this level of automation is possible with their current setup.
Hi Folks I have installed the m365 Email Phishing plugin from the CS store and hoping to use this within a SOAR automation that allows us to let the SOAR do initial triage using Virus Total and hopefully do some email display name checks to look at VIP members of staff before then sending it to our Jira queue if it detects anything potentially suspicious on the email. My question is, is this possible or am I expecting too much? We have E5 licenses and only run CS XDR with the free NGSIEM module. Bonus: If anyone has a github repo with some SOAR yamls to look at that would be great