Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
Interactive tour · 3 minutes · no signup

Watch the Familiar triage a phish.

One reported phishing email, end to end. You ask in plain English, the Familiar plans before it acts, you approve the one step that needs a human at the Seal, and the receipt shows everything. This is the product on demo data, not a video.

Skip to a live demo
1 / 6
Skip to demo
app.soarcery.ai/mail/reported
LowExternal sender banner added to newsletter · mail · 41m
MediumDMARC failure from a partner domain · mail · 24m
HighReported phish: "unpaid invoice" with attachment, 3 mailboxes · mail · just now
LowSpam quarantine digest ready for review · mail · 1h
MediumLook-alike domain seen in a signature block · intel · 2h
reported items · demo data
Step 1 of 6 · The trigger

A user reports a phishing email.

It reads like an unpaid-invoice notice with an attachment, from a sender the user did not recognize. Three people got it; one clicked away from handing over credentials. In most inboxes this now waits for an analyst to have a free minute.

Here it becomes a case the moment it lands. Every report gets the same full triage, including the ones that turn out to be nothing.

Why it matters: triage by sampling is how real phish get through. Triage that costs seconds instead of analyst minutes means nothing waits and nothing is skipped.
app.soarcery.ai/familiar
You asked the Familiartriage this reported phish and contain it if it is real.
Plan · awaiting your approval
  1. Pull the reported message and its attachment from mail.
  2. Detonate the attachment in a sandbox.
  3. Check the reply-to domain for typosquatting and enrich every indicator across intel.
  4. If it is a real threat, propose containment and stop at the Seal.
Tools: sandboxintelmailidentity

Assumptions: the report is good faith, containment is reversible, and nothing consequential runs without your approval.

or edit any step
plan-first · demo data
Step 2 of 6 · The ask

You ask in plain English. It plans before it acts.

No playbook to author, no rules to wire. You tell the Familiar the outcome you want, the way you would tell a teammate: triage this reported phish and contain it if it is real.

It answers with a plan, not an action: the steps it will take, the Tools it will use, and the assumptions it is making. You approve it, edit any step, or reject it. This plan is the Spell it will cast across your stack.

Why it matters: plan-first is the line between automation you can trust and automation you have to watch. You see the work before it happens, and nothing consequential is decided for you.
app.soarcery.ai/cases/CS-204
the Familiar09:14:12
Pulled the reported message and its attachment from mail. Extracting the sender, the reply-to, the links, and the attachment for the plan.
mail.get_message(1)380ms · ok
the Familiar09:14:31
The reply-to domain is a look-alike of a known brand and was registered days before it was first used: intel · look-alike of a known brand domain age · registered 4 days ago
intel.lookup(reply-to domain)610ms · ok
A brand-shaped domain registered days before it was used to send invoice lures fits a credential-phish setup. It is a strong signal on its own, but a domain being young is not proof of intent, so the next step is to detonate the attachment and watch what it actually does before calling it.
the Familiar09:14:52
Detonated the attachment in a sandbox. It opens a credential-harvest page and beacons to the same look-alike domain. Four extracted indicators match a public blocklist. sandbox · credential-harvest behavior blocklist · 4/4 indicators matched
sandbox.detonate(attachment)8.4s · ok
the Familiar09:15:04
Checked identity and mail logs for all three recipients: no one entered credentials, and no new sessions from unfamiliar networks.
identity.search(recipients, 24h)1.1s · ok
the case thread · demo data
Step 3 of 6 · The work

It works the plan and cites every step.

This is the part legacy automation never did: the actual thinking. The Familiar detonates the attachment in a sandbox, checks the reply-to domain for typosquatting, and enriches every indicator across intel. Evidence accumulates, and each claim is pinned to the Tool result behind it.

Open the show reasoning toggle on the domain check: nothing here asks for your trust, it shows you the work instead.

Why it matters: "the Familiar decided" is not a sentence you can take to an audit at 2am. Reasoning and citations you can read are what make the verdict yours to check.
app.soarcery.ai/cases/CS-204

Confirmed phish, three mailboxes affected

confidence: high
  • Reply-to domain is a look-alike of a known brand, registered 4 days ago.
  • The attachment opens a credential-harvest page when detonated in the sandbox.
  • All four extracted indicators match a public blocklist.
  • No recipient entered credentials. No sessions from unfamiliar networks.
Proposed: quarantine the message in all three mailboxes, block the reply-to domain, and file a ticket to IT. All three are reversible, and all three wait for the Seal.
branch · if the verdict came back benign, there is nothing to approve. The Familiar closes the case on its own and files the receipt.
the verdict · demo data
Step 4 of 6 · The verdict

A verdict you can read, with the evidence attached.

The output is a verdict in plain language: what it found, the evidence for it, how confident it is, and what it proposes to do. Confirmed phish, high confidence, containment recommended.

Notice what it does not do. Quarantining mailboxes and blocking a domain touch real users, so those actions wait. The verdict recommends; the Seal decides. And had the evidence come back benign, there would be nothing to approve at all.

Why it matters: a single risk score hides the doubt. A verdict with its evidence listed can be challenged, defended, and learned from.
app.soarcery.ai/seal
SEAL-2031 · CS-204consequential actionexpires in 52m
mail.quarantine_message(mailboxes: 3) · intel.block_domain(reply-to) · reversible: true

Confirmed phish, high confidence. Quarantine removes the message from all three inboxes before anyone clicks, and the reply-to domain is blocked at the mail gateway. Both are reversible: one action restores them if the verdict changes.

Approved by you · just now · recorded on the receipt
the Seal · demo data · this button is yours
Step 5 of 6 · The Seal

One step needed a human. It is yours.

Two minutes of work happened without you. This is the moment that should not: an action that touches three mailboxes and blocks a domain stops at the Seal, with the evidence and the blast radius in front of you.

You set where the Seal sits, per outcome. Teams start with everything sealed, watch the Familiar be right, and grant more autonomy at their own pace. Go ahead, approve it.

Why it matters: autonomy is a dial you control, not a switch a vendor flips. The Seal is how the Familiar earns trust instead of demanding it.
app.soarcery.ai/cases/CS-204 · receipt
09:14:02Reported phishing email received, 3 mailboxes affectedsource: mail
09:14:08Ask received in plain English; the Familiar posted a plan, you approved itplan-first · human approved the plan
09:14:31Reply-to domain enriched: look-alike of a known brand, registered 4 days agointel.lookup · 610ms
09:14:52Attachment detonated: credential-harvest behavior, 4/4 indicators on a blocklistsandbox.detonate · 8.4s
09:15:12Verdict posted: confirmed phish, confidence highevidence and reasoning attached
09:15:38Containment approved by a human at the SealSEAL-2031 · identity recorded · reversible action
09:15:40Quarantined in 3 mailboxes, reply-to domain blocked, ticket filed3 actions · all reversible · case closed
98sreport to closed
6tool calls cited
1human decision
100%of it on the receipt
the receipt · exportable · demo data
Step 6 of 6 · The receipt

Every step. Every source. Every decision. One receipt.

The whole case, from the report landing to the mailboxes cleaned, is one replayable record: what the Familiar planned, what it ran, what each Tool returned, and which human approved the action that mattered.

Hand it to an auditor. Replay it after a review. Or read it with your coffee, because the case closed in ninety-eight seconds and no one on your team touched a console.

Why it matters: when a product says autonomous, ask to see this. If it cannot show you the receipt, what it is selling is trust without evidence.
That was one report

Yours arrive by the thousand.
Bring one and watch the Familiar work it.

A 30-minute walkthrough on your real triage flow, with the same receipts at the end. Technical, not a pitch.

Prefer to read how it works first?