Auto-triage phishing reports with VirusTotal and Slack

By General Input

Every 15 minutes, phishing emails your staff forward in get checked against 70+ security engines and summarised in Slack, with a compliance log kept automatically.

Integrations

  • VirusTotal
  • Gmail
  • Slack Bot
  • Google Sheets

Type

Agentic Task

Categories

  • Engineering
  • Operations

Every 15 minutes, triage the phishing reports our staff forward into our shared security mailbox. Use the Gmail List Messages operation to find unread messages carrying the "Phishing Reports" label. Process at most five messages per run, oldest first, so a backlog drains steadily across runs instead of exhausting our VirusTotal quota in one burst.

For each message, use Gmail Get a Message at full detail to read the sender address, the subject, the date received, and the body. Extract every link in the body, including links hidden behind display text, and note who forwarded the report. Note every attachment, and use Gmail Get Attachment to retrieve each one so you can compute its SHA-256 hash.

Check each extracted link with VirusTotal. Submit it with Scan a URL, which returns an analysis id, then poll Get an Analysis until the status comes back as completed. VirusTotal scans are not always immediately available, so wait roughly fifteen seconds between polls and give up after about five attempts rather than looping forever. For links VirusTotal already knows about, and whenever polling is exhausted, fall back to Get a URL Report to read the stored verdict. Deduplicate links so the same URL is only checked once per email.

For each attachment, look up its hash with VirusTotal Get a File Report. A not-found response means VirusTotal has never seen that file, which is worth reporting as unknown rather than treating it as clean.

Weigh the per-engine detection counts from each report. Treat an indicator as malicious when three or more engines flag it, suspicious when one or two engines flag it or when the file is unknown, and clean when nothing is flagged. The verdict for the whole email is the worst result across all of its links and attachments. Include a one-line explanation of why you landed on that verdict.

Post a short summary to our security channel using Slack Bot Send a Message. Include the verdict, the sender, the subject, who reported it, and one line per link and attachment showing the detection count out of the total engines checked. Defang every URL and every domain so nobody clicks one by accident while reading the alert: write hxxp:// or hxxps:// in place of http:// or https://, and wrap each dot in square brackets, so example.com becomes example[.]com. Apply this to sender domains too. Lead with a clear visual marker when the verdict is malicious so it stands out in the channel.

Log one row per reported email to our compliance spreadsheet with Google Sheets Append Values, capturing the date triaged, the sender, the subject, who reported it, the number of links and attachments checked, the highest detection count seen, and the final verdict. Keep URLs defanged in the sheet as well.

Finally, relabel the message with Gmail Modify Message Labels: add our "Triaged" label and remove the "Phishing Reports" label along with the unread marker, so the same email is never picked up twice.

Pace the work against VirusTotal rate limits. A free key allows only four requests per minute and five hundred per day, so space the lookups out rather than fanning out all at once, and stop early if VirusTotal starts returning quota errors, leaving the remaining emails unread for the next run. If a single email fails to process, log the failure, leave it unread so it retries later, and carry on with the rest.

Related prompts

Explore more prompts
Call overdue Xero customers with an AI collections agentLocal listing health board for every location you manageWin back LiveChat visitors whose chats went unansweredLet support send one-off Loops emails without an engineerA brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensStop cold emails to anyone with a live deal in PipedriveLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reason