logo

NJP

Cofense Triage Security Incident Response

Cofense Triage Security Incident Response

by Cofense Inc

Cofense Triage™ Automate your phishing email analysis

0 installs 0 reviews v1.3.1 Scoped Application Free (integration tables[21] not counted) 21 tables

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 24 -24
18 days of no change
2026-04-08 25 -1
2026-04-07 26 -1
67 days of no change
2026-01-29 27 -1
6 days of no change
2026-01-22 28 -1
33 days of no change
2025-12-19 30 -2
80 days of no change
2025-09-29 29 +1
217 days of no change
2025-02-23 28 +1
23 days of no change
2025-01-30 27 +1
91 days of no change
2024-10-30 26 +1

About

Cofense Triage™, phishing detection and response (PDR) platform, accelerates phishing email identification and mitigation. Cofense Triage finds the phish that secure email gateways (SEG) miss. With Cofense Triage, security teams speed analysis of user-reported emails, find real phish faster, and respond more effectively. Cofense Triage gives incident responders the ability to act on all phishing alerts quickly by automating threat qualification and investigation. SOC teams can focus on interpreting results and responding to phishing threats effectively. As soon as a suspicious email gets reported, thousands of intelligence-driven YARA rules automatically assess the report, clustering it with reports containing similar payloads, and surfacing the highest priority threats for immediate action.

The integration with ServiceNow Security Incident Response (SIR) allows SOCs to ingest reported phishing emails from Cofense Triage’s inbox, reconnaissance, and processed queues. Security incident response tickets can be created based on the threats uncovered by Cofense Triage, starting at the cluster level. SOC analysts working incidents in ServiceNow will be able to view the email threat, download attributes, ingest threat indicators, run playbooks, prioritize workflow based on security categorization and severity, and bidirectionally communicate with Cofense Triage to update reporting phishing incidents. Empower SOCs with Cofense Triage industry-leading phishing-specific analysis and response and operationalize incident response workflow with ServiceNow Security Incident Response.

Key Features

- Ingest employee-reported phishing emails from Cofense Triage™ based on severity, category, threat indicators, and reporter reputation.
- Create security incidents in ServiceNow Security Incident Response (SIR) from events in Cofense Triage’s inbox, reconnaissance, and processed queues (including clusters)
- Ingest phishing threat indicators (including 2nd stage indicators found in report comments) from Cofense Triage into ServiceNow SIR to enrich and operationalize incident response.
- Run Cofense Triage playbook from ServiceNow SIR to categorize reports, respond to reporters, and tag reports and clusters in Cofense Triage.
- Update and process phishing emails in Cofense Triage from ServiceNow SIR.
- Bidirectionally manage phishing threat indicators and observables between Cofense Triage and ServiceNow SIR

Version History (1)
v1.3.1 2025-07-23 14:47:31
Provided support of Yokohama release Bug fixes
ID: a79df209db98a05066a1f6a4e296197b · Published: Jul 2025 · Updated: Sep 09, 2026