Cutting Phishing Triage From Minutes to Under 30 Seconds by Kiell TampubolonCutting Phishing Triage From Minutes to Under 30 Seconds by Kiell Tampubolon
Cutting Phishing Triage From Minutes to Under 30 Seconds
Every phishing report landing in a SOC inbox has to be manually opened, with headers inspected by hand -- SPF, DKIM, DMARC, sender reputation, all checked one at a time. At scale, that is minutes of analyst time per ticket, multiplied by hundreds of reports a week.
What I Built
An automated triage engine that parses email headers, runs SPF/DKIM/DMARC authentication checks, and cross-references KnowBe4 phishing simulation data to return a verdict automatically, built with Python, Power Automate, and Copilot Studio.
The Result
Triage time dropped from several minutes per ticket to under 30 seconds, with no loss in detection accuracy, freeing analysts to focus on the reports that actually need human judgment.
What This Means For You
If your security or IT team is drowning in phishing reports, I can build the same kind of automation into your existing stack (Microsoft 365, Google Workspace, or your SIEM) to cut response time without adding headcount.
Like this project
Posted Sep 16, 2026
Automated phishing triage engine that dropped analyst response time from minutes to under 30 seconds per ticket.