Skip to main content
xorlab Security Platform enriches records of a processed email with information it extracts from the email content, metadata, and existing email history. Enrichment happens in the form of hashtags. You can access the tag information in the record details or, if integrated, in your Security Information and Event Management (SIEM). Use Search to find emails tagged with certain keywords or to aggregate similar emails (e.g., belonging to the same marketing or phishing campaign). You can make xorlab Security Platform add custom tags (please see Custom Alerts) to the processed email records.

Aggregation examples

#inc #highrisk #untrusted #newsender #newdomain #exposedhvt
Aggregates all incoming emails from untrusted senders, from which we have not yet received any email, to a high-value target and which have a high-risk score and contain a link to a domain not yet observed in email communication.
#inc #highrisk #untrusted #newsender #cloudstorage
Aggregates all incoming emails from untrusted senders, from which we have not yet received any email, which have a high-risk score and contain a link to a cloud storage service.
#inc #highrisk #untrusted #newsender #shortenednolocalreputation
Aggregates all incoming emails from untrusted senders, from which we have not yet received any email, which have a high-risk score and contain a shortened link to a URL that has no significance to your organization.
#inc #untrusted #newfiletype #exposedhvt
Aggregates all incoming emails from untrusted senders to a high-value target, which contain an attachment whose file type has never been observed in your organization’s email communication.
#out #encryptedfile #untrusted
Aggregates all outgoing emails to untrusted recipients which contain an encrypted attachment.
#inc #trusted #dangerousvbascript
Aggregates all incoming emails from trusted senders that contain a Microsoft Office document that contains a VBA script with high-risk functions.
#pdf #cfiviolation
Aggregates all emails with a PDF attachment that triggered a control flow integrity violation in the Sandbox.

Tag reference

Here is a list of all keyword tags that are used to enrich email records.

General classification tags

Use caution when using verdict classification tags in campaigns, as some of the tags are applied after the campaigns are evaluated (e.g. #internal and #benign). This can result in discrepancies between search queries that match emails and campaigns that modify email verdicts.

Content classification tags

Attachment classification tags

URL classification tags

Sandbox

Relationship tags

Relationship tags describe the quality of the relationship between your organization and the sending organization (or the receiving organization for outgoing emails). Tag assignment can be influenced by configuring the corresponding thresholds.

Sender-specific tags

Recipient-specific tags

The following tags are only available on outgoing emails.

Mail flow tags

Mail flow tags indicate if an email was sent or received by your organization, exchanged internally, or processed on behalf of a third party. Please see Search.

Decision tags

Decision tags indicate if an email was delivered, sanitized, or quarantined after processing.

Risk scores

Overall risk

Phishing risk

Spam risk

The spam risk of an email is influenced by a variety of factors. Two of them are the scores calculated by SpamAssassin and Rspamd. The following tags describe them:

User reports

Reporting misclassification