7-step guided workflowTriage, Header Analysis, URL Triage, Attachment Sandbox, Identity/Okta Impact, Containment, and Closure, each with its own fields, checklist, and escalation criteria.
Live IOC aggregatorSenders, IPs, URLs, hashes, C2 indicators, and affected users collect automatically as you fill in each step, ready to copy in one block.
Automated EML parsingDrop a raw email and get SPF/DKIM/DMARC, sender, URLs, and attachment SHA256 hashes extracted client-side. Nothing is uploaded to any server.
Forwarded-report detectionA user-forwarded phishing report is unwrapped automatically, so the real sender and URLs get analyzed, not the forwarding wrapper.
Live threat intel enrichmentEvery domain, URL, IP, and file hash is checked against VirusTotal and RDAP domain-age data, with optional URLScan submission, using your own free API keys.
Computed risk scoreAuth failures, flagged indicators, and domain age combine into a single 0-100 risk score with a CRITICAL/HIGH/MEDIUM/LOW verdict.
Key importImport your VirusTotal and URLScan keys at once from a JSON, TXT, CSV, or Markdown file instead of typing them in.
Export anywhereCopy IOCs, copy the full report to clipboard, or download it as a standalone Markdown file for your ticketing system.
Runs entirely in your browserNo account, no backend server for PHISHOPS itself. The only network calls are the ones you configure, to VirusTotal, URLScan, and RDAP.