Hoxhunt Respond automates phishing triage and email removal

Hoxhunt Respond automates phishing triage and email removal

Hoxhunt has added new capabilities to Hoxhunt Respond, its platform for automating email incident response in security operations centers (SOCs). According to the company, Respond can cut the number of phishing tickets that need an analyst's attention by up to 99% and remove confirmed malicious campaigns from inboxes in under one minute.

The update is aimed at a side effect of successful security awareness training. When employees learn to spot and report suspicious messages, the volume of reports reaching the SOC grows with them.

The cost of good reporting habits

Better reporting brings more triage work. One phishing campaign can lead to hundreds of near-identical reports from different employees, and each one may become a separate ticket.

Most of those reports turn out to be harmless. Hoxhunt's own data shows that about 80% to 85% of emails flagged by employees are benign. Analysts still have to look at them, which takes time away from investigating real threats such as hijacked accounts sending phishing emails from trusted senders.

Respond is designed to sort through that volume before it reaches a human. It investigates each reported email automatically, groups related messages into one incident at the campaign level, and filters out duplicate or safe reports.

When a threat is confirmed, the platform searches the affected inboxes for matching messages and deletes them. The removal can be reversed, and employees who reported the email receive feedback right away.

Four components

Hoxhunt splits Respond into four core products:

  • Instant Feedback: gives employees immediate responses when they report real threats. It is modelled on the reward-based approach Hoxhunt uses in its phishing simulations and is meant to make the reporting behavior stick.
  • Incident Orchestration: classifies reported emails, links related reports and ranks incidents. Analysts get a single campaign-level view instead of hundreds of separate tickets.
  • Search & Destroy: finds confirmed malicious messages across inboxes and removes them within seconds. This includes copies that nobody has reported.
  • Feedback Rules: recognizes known-safe messages and sends employees customizable feedback straight away. This reduces false alarms while still encouraging people to report.

"Getting employees to habitually report suspicious emails is one of the biggest wins we can achieve in cybersecurity, and a surge of threat intelligence should help, not hinder, the SOC," said Mika Aalto, CEO of Hoxhunt.

"Hoxhunt transforms the workforce into a distributed network of threat sensors, and Respond finds the signal so the SOC can quickly respond, without generating more manual work. One employee can spot the attack, and automation can remove it for everyone else," he added.

Trained on a decade of reports

The models behind Respond are trained on 10 years of real phishing emails reported by employees, along with intelligence from more than five million "human sensors", as Hoxhunt calls the users who report suspicious messages.

The company says the platform classifies malicious emails with 96% accuracy and safe emails with more than 99% accuracy. At enterprise customers, Respond has been documented to save more than 900 hours of SOC analysis work per month.

Our Take

The pitch behind Respond addresses a real tension. Organizations spend money training staff to report phishing, and then the SOC struggles to handle the reports. If most reported emails are harmless, as Hoxhunt's figures suggest, automated triage is an obvious place to save analyst time.

The launch also fits a wider pattern of security vendors moving routine SOC work to automation and AI models, from AI-driven threat hunting to case handling. That trend has a downside, which we noted in a recent survey showing that entry-level analyst jobs are getting harder as simpler tasks disappear.

The accuracy figures deserve a closer look. A 96% detection rate for malicious emails still leaves some room for misses, so teams will likely want to know how unclear cases are escalated. The reversible remediation suggests Hoxhunt expects some mistakes. It is worth watching whether independent customer results match the vendor's figures for ticket reduction and time saved.