Cutting Phishing Triage From Minutes to Under 30 Seconds by Kiell TampubolonCutting Phishing Triage From Minutes to Under 30 Seconds by Kiell Tampubolon

Cutting Phishing Triage From Minutes to Under 30 Seconds

Kiell Tampubolon

Kiell Tampubolon

The Problem

Every phishing report landing in a SOC inbox has to be manually opened, with headers inspected by hand -- SPF, DKIM, DMARC, sender reputation, all checked one at a time. At scale, that is minutes of analyst time per ticket, multiplied by hundreds of reports a week.

What I Built

An automated triage engine that parses email headers, runs SPF/DKIM/DMARC authentication checks, and cross-references KnowBe4 phishing simulation data to return a verdict automatically, built with Python, Power Automate, and Copilot Studio.

The Result

Triage time dropped from several minutes per ticket to under 30 seconds, with no loss in detection accuracy, freeing analysts to focus on the reports that actually need human judgment.

What This Means For You

If your security or IT team is drowning in phishing reports, I can build the same kind of automation into your existing stack (Microsoft 365, Google Workspace, or your SIEM) to cut response time without adding headcount.
Like this project

Posted Sep 16, 2026

Automated phishing triage engine that dropped analyst response time from minutes to under 30 seconds per ticket.