Cofense Triage - 2 years after
Use Cases and Deployment Scope
We utilize Cofense Triage platform to help us dealing with user-reported emails. Platform is automatically grouping reported emails into so-called clusters, based on sender. (This allows bulk-processing of the emails)
It also enables automatic categorization of emails based on set of predefined and custom rules which streamlines triage process.
Lastly, platform allows automatic response to be sent to the end-user based on defined criterias.
Using Cofense Triage allows us to triage a subset of incoming reports and identify real phishing cases amongst those
Pros
- Grouping of incoming reports
- Overview of metadata related to email, including rendered preview
- Informative dashboard with quite some indicators available for selection
Cons
- Product support could be better - there was an issue with some user accounts which was not resolved for a very long time
- Lacking AI\ML capabilities - platform requires continuous efforts to be invested by the personnel in order to keep the quality of rules\automations high
- Automatic remediation (e.g. purge of emails from mail server) of confirmed Phishing cases is not available - this is a separate product
Likelihood to Recommend
The tool is very helpful in improving Phishing detection capabilities as it streamlines the process of analyzing user reports a lot. Besides it has a built-in mechanism of rating reporters(end-users) based on their historical performance. Downside - tool requires continuous resource investment to deliver best result.
Tool is not helping too much in improving user-education, because automated response process is not immediate and is prone to errors.
