Automated EML parsingDrop a raw email and get SPF/DKIM/DMARC, sender, URLs, and attachment SHA256 hashes extracted client-side. Nothing is uploaded to any server.
Forwarded-report detectionA user-forwarded phishing report is unwrapped automatically, so the real sender and URLs get analyzed, not the forwarding wrapper.
Live threat intel enrichmentEvery domain, URL, IP, and file hash is checked against VirusTotal and RDAP domain-age data, with optional URLScan submission, using your own free API keys.
Computed risk scoreAuth failures, flagged indicators, and domain age combine into a single 0-100 risk score with a CRITICAL/HIGH/MEDIUM/LOW verdict.
Key importImport your VirusTotal and URLScan keys at once from a JSON, TXT, CSV, or Markdown file instead of typing them in.
Export anywhereCopy the full report to clipboard, or download it as a standalone Markdown file for your ticketing system.
7-step guided workflowThe MANUAL TRACKER mode covers Triage, Header Analysis, URL Triage, Attachment Sandbox, Identity/Okta Impact, Containment, and Closure, each with its own checklist and escalation criteria.
Live IOC aggregatorIn manual mode, senders, IPs, URLs, hashes, C2 indicators, and affected users collect automatically as you fill in each step.
Runs entirely in your browserNo account, no backend server for PHISHOPS itself. The only network calls are the ones you configure, to VirusTotal, URLScan, and RDAP.