New release : CTI Report - Pharmaceutical and drug manufacturing 

                 Download now

Combating Phishing: How Intrinsec and GLIMPS Automate the Processing of User Reports

Despite increasingly sophisticated filtering solutions, malicious emails continue to reach employees' inboxes. When employees report them, the challenge lies in being able to process these alerts quickly, effectively, and without breaking the budget. That's precisely the promise of PhishReport, Intrinsec's offering, which is based on analytics technology GLIMPS to automatically classify suspicious emails reported by users.

Reporting, the weak link in the fight against phishing

Phishing remains one of the primary attack vectors. To combat it, organizations have implemented numerous safeguards, from filtering gateways and email protection to employee awareness training. These measures are essential, but none are foolproof. Some malicious emails still slip through the net and reach users.

The good news is that more and more employees are spotting and reporting suspicious messages, often with a simple click on the report button in their email. Companies that run awareness campaigns against phishing are even seeing this reporting rate climb significantly.

But this virtuous reflex immediately raises a question, What should be done with all these reports?

  • A considerable workload. Each reported email must be analyzed. Manually, processing a single alert requires an expert to spend an average of several tens of minutes.
  • An expensive device. Maintaining a team or service provider dedicated to this task represents a high recurring budget, difficult to justify given a largely repetitive activity.
  • A lack of visibility. Without the right tools, these reports offer little usable feedback to the security teams.

It is from this shared observation that the idea of standardize and automate This treatment aims to relieve the burden on teams and make this service accessible at a controlled cost. Intrinsec and GLIMPS have combined their expertise to meet this need.

A multi-year collaboration between two French cybersecurity players

Intrinsec and GLIMPS have been collaborating for several years, and PhishReport is the most concrete outcome of this partnership.

Intrinsic is a French pure-play cybersecurity company, qualified PASSI High, PRIS High, and PACS, covering the entire spectrum from offensive (penetration testing, Red Team, Purple Team) to consulting and GRC, including detection (SOC), cyber threat intelligence (CTI), and incident response (CERT). The company operates its own generative AI platform in an environment SecNumCloud.

GLIMPS, PhishReport, a specialist in detecting malware in files using artificial intelligence, brings its in-depth analysis technology, capable of identifying malicious content where traditional approaches reach their limits. This analytical component is precisely one of the core strengths of PhishReport.

Intrinsec offers a service offer high-value assets, and GLIMPS handles the analysis phase. The client subscribes to a turnkey service; the technology operates behind the scenes.

How does PhishReport work?

PhishReport integrates directly into the environment Microsoft 365. For the user, nothing changes; they continue to use the report button in their Outlook.

Behind the scenes, each reported email enters a fully automated, three-stage pipeline.

  1. Pre-analysis by AI. Intrinsec's AI agents, based on LLMs, perform an initial evaluation of the email and its attachments, taking into account technical and semantic criteria, and produce a score.
  2. In-depth analysis by GLIMPS. Based on this score, risky attachments are sent to GLIMPS for in-depth inspection. Using over 25 detection and analysis engines, including 8 proprietary AI models, GLIMPS delivers a simple verdict to Intrinsec agents in 3 seconds: safe, malicious, or suspicious. In addition, the threat is contextualized using Indicators of Convergence (IoCs), MITRE ATT&CK mapping, and malicious code identification.
  3. Conclusion and recommendation. The AI takes over, cross-references its pre-analysis with the GLIMPS verdict, and formulates a detailed conclusion indicating whether the email is malicious, why, and what action to take.

Following the analysis, two scenarios emerged.

  • If the email is deemed harmless, It is returned to the user, along with instructions for use.
  • If the email is malicious, The client's security team is alerted, and an incident is created on Intrinsec's Cyboard platform, with all analysis elements and indicators of infection (IOCs) extracted. When the report is made via Outlook's native button, as recommended, the email client automatically quarantines the email in the reporting user's inbox; other inboxes that received the same message are not covered by this automatic quarantine and remain the responsibility of the security team.

In both cases, the user receives an acknowledgement of receipt followed by a notification of conclusion, so that he knows that his report has been taken into account and that he reacted correctly.

The automated chain doesn't just distinguish between harmless and malicious activity. It delivers a reasoned conclusion, extracted indicators, and recommendations directly usable by security teams. This is the core function of the analysis engine built by Intrinsec, designed to handle the volume of reports and make each alert actionable without further intervention.

There remain the much rarer situations where the issue extends beyond the email itself. It's necessary to know who else was targeted by the same campaign, whether a link was clicked or an attachment opened, and how far the attempt may have gone. In these cases, teams can call upon an Intrinsec analyst, who reviews the case and determines its true scope.

Intrinsec and GLIMPS, the winning partnership

By combining Intrinsec's AI orchestration and GLIMPS's analysis, PhishReport delivers three concrete benefits.

  • Drastically reduce response time from several tens of minutes in manual treatment to a few minutes.
  • Relieve the security teams, which are only called upon in the event of proven phishing, and can finally process reports that were previously left aside.
  • Controlling the budget, the cost of the service representing only a fraction of that of an equivalent manual treatment.

Data sovereignty and confidentiality are at the heart of the system.

Because it involves processing potentially sensitive emails, control of the processing chain is essential. Intrinsec operates its own generative AI platform, from the web application to the APIs. In-depth analyses are handled by GLIMPS, which runs in a closed environment, without reuse or resale of customer data, on servers hosted in France and Europe.

Two French players and clear commitments on data constitute a real asset, in a context where digital sovereignty is no longer an option.

phishreport

Conclusion

Phishing isn't going away, and user reports will continue to rise. The real question is no longer «"How should we receive them?"» but «"How can we process them on a large scale, quickly and at a controlled cost?"». This is the whole purpose of PhishReport, and this is the meaning of the partnership between Intrinsec and GLIMPS, which puts the complementarity of their technologies at the service of more effective and more accessible cybersecurity.

Want to learn more about PhishReport? 

Articles by category