← All use cases

Email SecurityNew

LimaCharlie Email Security protects Microsoft 365 and Google Workspace mailboxes from inside the same tenant, permission model, and telemetry lake as the rest of your security operations. Every message gets an explainable verdict, lands as a searchable event, and sits one click or one detection rule away from quarantine. Because email events share a lake with endpoint, cloud, and identity telemetry, a phish that leads to a new binary running on the recipient's laptop is something a single rule can catch.

How it runs on LimaCharlie
01

Connect a Workspace

Add a Microsoft 365 or Google Workspace tenant with an API credential. The connection reads mail through the provider's API, so MX records and mail routing stay exactly as they are. A connection test checks every permission the collector needs and reports each one individually. Connections, policy, and custom rules are stored as Hive records, which makes the full configuration API-first and git-syncable across every tenant you manage.

02

Backfill Messages

Mailboxes are discovered and subscribed automatically, and up to 14 days of historical mail is judged with the same rules as live traffic. Backfilled messages are scored without triggering alerts or actions, so the queue starts with real verdicts and sender-history signals have two weeks of context the moment live mail arrives.

03

Judge

Each message is parsed, enriched, and scored into one verdict: malicious, suspicious, graymail, or benign. Enrichment covers sender and domain history, VIP and lookalike-domain impersonation, domain registration age, link features, and attachment explosion, including recursive archive unpacking, macro extraction, QR code decoding, and file typing by content. Attachments run through Strelka against your own YARA rules, the same ones your endpoints use. Every non-benign verdict shows the signals that produced it and the weight of each.

04

Remediate

Quarantine, trash, move to spam, restore, or apply a warning banner at the provider. Banners accept HTML with your own branding, and the original message content is sanitized so an attacker can't forge a banner of their own. Actions run from policy, the console, a D&R rule, the API, or the CLI, and each one is written to an audit trail. Policy ships in alert-only mode, so nothing moves until you switch it to enforce.

05

Sweep campaigns and reports

Messages the engine attributes to one attack are clustered into a campaign, so a phish that hit forty mailboxes is triaged once and swept once. The abuse mailbox becomes an SLA queue, with each user report joined back to the original message across the tenant.

06

Correlate across domains

Message, verdict, action, and user report events land in the same lake as EDR, cloud, and identity telemetry. Pivot from a delivered phish to the recipient's endpoint, confirm whether the attachment executed, and respond on both from the same rule set. The same lookups and threat feeds drive mail rules and endpoint rules, so one phishing-domain list synced from GitHub flags the inbound message and the endpoint DNS request that follows it. A multi-stage rule can chain a suspicious delivery to a risky Microsoft 365 sign-in by the same user, then to the recipient's machine resolving the phish URL, and isolate that host.

AI triage

AI triage runs as a standard LimaCharlie AI agent on the model and provider you choose, starting from a reviewed reference agent you can edit or replace. The agent's API key decides whether it can act. A passive agent that tries to move mail is refused server-side and the attempt is audited, so you can read its conclusions for as long as you like before widening the key.

What it costs

Email Security is priced at $1 per protected inbox and billed through the same LimaCharlie account as the rest of the platform. Attachment analysis, the built-in rule pack, and your own D&R rules, YARA rules, and lookups are included, so a service provider can cover every customer mailbox without passing a separate vendor invoice through. AI triage runs on your own model provider, and each agent carries a per-run budget ceiling that stops a session when it is reached.

Where it sits

Email Security analyzes mail after the provider delivers it, typically within seconds, and works behind Exchange Online Protection, Defender, or Gmail's own filtering. Remediation removes a message from the inbox after it lands. Message events are kept for a year as an immutable record, retention on the working queue is configurable, and permissions decide who can view, download, or act on a message.

Cloud SecurityAI-Assisted InvestigationSOAR / Automation
DOCSEmail Security overviewDOCSGetting startedDOCSEvents and automationDOCSCampaignsDOCSAI triageGITHUBReference AI triage agent (lc-ai)

Connect a Microsoft 365 or Google Workspace tenant, or walk through it with a solutions engineer.

Start freeBook a demo