Hoxhunt expands Respond to automate phishing investigations and email removal
Hoxhunt expanded Respond to automatically investigate reported phishing and remove confirmed malicious email within a minute.
Hoxhunt expanded Hoxhunt Respond, which automatically investigates employee-reported emails, groups related messages into campaign incidents, and suppresses benign or duplicate reports. The company says it can reduce phishing tickets needing analyst attention by up to 99% and remove confirmed malicious messages, including unreported copies, in under one minute. Its models are trained on 10 years of reported phishing and intelligence from more than five million people, with claimed accuracy of 96% for malicious mail and over 99% for safe mail. Hoxhunt also says the platform has saved enterprises more than 900 SOC analysis hours per month.
- Respond can cut analyst-facing phishing tickets by up to 99%.
- Confirmed campaigns are removed from inboxes in under one minute.
- Hoxhunt says 80% to 85% of reported emails are benign.
- Models claim 96% malicious and over 99% safe-email accuracy.
- Platform reportedly saved enterprises over 900 SOC hours monthly.
Full article365 words · extracted from helpnetsecurity.com · click to collapse
Hoxhunt has announced expanded capabilities for Hoxhunt Respond, its email incident response automation platform for security operations teams. Respond can reduce phishing tickets requiring analyst attention by up to 99% and remediate confirmed malicious campaigns in under one minute.
Effective phishing training creates a valuable result: employees recognize and report more real threats. It also creates more work for the security operations center. A single campaign can generate hundreds of duplicate reports, while Hoxhunt data shows that roughly 80% to 85% of all employee-reported emails are benign.
Respond automatically investigates each reported email, groups related messages into a single campaign-level incident and suppresses safe or duplicate reports. Once a threat is confirmed, it finds matching messages across affected inboxes and removes them automatically, with reversible remediation and immediate feedback for employees.
Hoxhunt Respond includes four core products:
- Instant Feedback: Employees receive in-the-moment feedback on their real threat reports, mirroring the reward-based skill building in the simulated environment to lock in behavior change.
- Incident Orchestration: Classifies reported emails, correlates related reports, and prioritizes incidents so analysts receive a clean, campaign-level signal instead of hundreds of individual tickets.
- Search & Destroy: Locates and removes confirmed malicious messages across inboxes in seconds, including copies that employees have not reported.
- Feedback Rules: Identifies known-safe communications and gives employees immediate, customizable feedback, reducing false alarms while reinforcing the reporting habit.
“Getting employees to habitually report suspicious emails is one of the biggest wins we can achieve in cybersecurity, and a surge of threat intelligence should help, not hinder, the SOC,” said Mika Aalto, CEO of Hoxhunt. “Hoxhunt transforms the workforce into a distributed network of threat sensors, and Respond finds the signal so the SOC can quickly respond, without generating more manual work. One employee can spot the attack, and automation can remove it for everyone else.”
The Hoxhunt Respond platform has been documented to save more than 900 hours of SOC analysis per month at enterprise companies.
Hoxhunt analyzes reported emails using models trained on 10 years of real employee-reported phishing data and intelligence from more than five million human sensors. The platform classifies malicious emails with 96% accuracy and safe emails with more than 99% accuracy.