Back to Blog
October 5th, 2026

Announcing LimaCharlie Email Security: Natively Integrated Into Your SecOps Stack

Picture of Christopher Luft
Christopher Luft

Co-founder & CCO

LimaCharlie Email Security Launch

LimaCharlie Email Security is generally available today. It protects Microsoft 365 and Google Workspace mailboxes from inside the same tenant, permission model, and data lake as the rest of LimaCharlie. A phishing email and the endpoint activity it causes can now be detected, investigated, and remediated in one place.

Email has been the blind spot in the SOC's data

A phishing email is often the first step in an intrusion, yet in most stacks email security runs as a separate product with its own console. The email tool can tell you a message was malicious. It usually can't tell you whether the recipient opened the attachment, whether that attachment executed, or which systems the compromised account can reach. Answering those questions means exporting alerts, switching consoles, and correlating by hand. For MSSPs, that work repeats for every client.

Emails are events

"Emails are events in a way. You want to do correlation, you want to do alerting, you want to do response on it."

Maxime Lamothe-Brassard, founder and CEO, LimaCharlie

That idea shapes the whole product. Every message LimaCharlie ingests is parsed, judged, and written to the same lake as your EDR, cloud, and identity telemetry. A detection like "a phish was delivered, then the recipient's endpoint ran a new binary" is a single detection and pivot in a single place. From there, an analyst or an AI agent can pivot from the message to the endpoint to the cloud resources that user can access, without leaving the platform.

The same lookups and YARA rules work on both sides. A phishing-domain feed synced daily from GitHub can flag an inbound message and the endpoint DNS request that follows it, and attachments are scanned with the same YARA rules your endpoints use.

How LimaCharlie Email Security works

Connect through the provider API

Add a Microsoft 365 or Google Workspace tenant with an API credential. MX records and mail routing stay exactly as they are. A connection test checks every permission the collector needs and reports each one individually. Up to 14 days of historical mail is then judged with the same rules as live traffic, so the queue fills with real verdicts shortly after you connect.

Get an explainable verdict on every message

Each message receives one verdict: malicious, suspicious, graymail, or benign. Verdicts come from a weighted managed rule pack plus any rules you write. Enrichment covers sender and domain history, VIP and lookalike-domain impersonation, domain registration age, link features, and attachment explosion, including recursive archive unpacking, macro extraction, and QR code decoding. Attachments are unpacked recursively through Strelka and scanned with your own YARA rules. Every non-benign verdict shows the signals that produced it and the weight of each.

Remediate with a full audit trail

Quarantine, trash, move to spam, restore, or apply a warning banner at the provider. You can trigger each action from policy, the console, a D&R rule, the API, or the CLI, and every action is audited. Policy ships in alert-only mode, so nothing moves until you switch to enforce.

Triage campaigns once

Messages from a single attack are clustered into a campaign, so a phish that hit forty mailboxes is triaged once and swept once. The abuse mailbox becomes an SLA queue, with each user report joined back to the original message across the tenant.

Run AI triage on your own terms

AI triage is a standard LimaCharlie AI agent running on the model and provider you choose. It starts from a reviewed reference agent that you can edit or replace. Because you choose the model and provider, you decide where message data is processed, which matters for customers with data residency requirements. The agent's API key decides whether it can act. If a passive agent tries to move mail, the request is refused server-side and the attempt is audited.

Manage everything as code

Connections, policy, and custom rules are stored as Hive records. Your email security configuration is API-first and syncs to git like the rest of your LimaCharlie deployment.

Built for service providers

For MSSPs and MDR providers, each client's mail tenant runs as its own LimaCharlie org, with its own policy, permissions, and audit trail. Package a baseline of connections, policy, and rules as code and deploy it to every client org. Email security arrives on the same platform and bill as the endpoint and cloud coverage you already deliver. At $1 per mailbox per month, an MSSP can price email security into a managed service with room for margin and cover every client mailbox on one bill.

Because email carries more sensitive information than most telemetry, access is split into separate permissions. Viewing the queue and the parsed message is one permission. Remediating live mail is another. Downloading a message's original bytes requires its own permission plus a logged justification.

Where it fits in your stack

Email Security analyzes each message as soon as the provider's API makes it available. It works behind Exchange Online Protection, Defender, or Gmail's own filtering and judges what those filters let through. Remediation removes a message from the inbox after it lands.

Pricing and availability

Email Security is available now for Microsoft 365 and Google Workspace at $1 per mailbox per month, billed through your existing LimaCharlie account. Attachment analysis, the built-in rule pack, and your own D&R rules, YARA rules, and lookups are included in that price. AI triage runs on your own model provider, and each agent carries a per-run budget ceiling.

See Email Security live

Emails Are Events: The Live Launch of LimaCharlie Email Security

On October 14, Maxime Lamothe-Brassard, founder and CEO, gives the first public demo of Email Security. He'll connect a live tenant, sweep a campaign, and follow a phish from the inbox to the endpoint. [Register here]

Integrated Email Security with LimaCharlie: Hands-On Workshop for MSSPs

On October 28, Sr. Solutions Engineer Ken Westin leads a hands-on session for service providers. Participants connect a live mail tenant, write custom signal and correlation rules, integrate IOC feeds, and manage configurations as code for reuse across client orgs. [Register here]

Get started with Email Security