Skip to content

Suspicious

AI-powered phishing & threat-analysis platform built by Thales Group CERT. Suspicious automatically inspects, classifies, and reports suspicious emails, files, URLs, IPs, and file hashes.

What it does

  • Analyzes suspicious content: emails, documents, URLs, IPs, and file hashes.
  • Runs deep analysis pipelines: YARA rules, sandboxing, metadata inspection, an AI email classifier, and Cortex analyzers.
  • Classifies results as Safe, Inconclusive, Suspicious, or Dangerous.
  • Provides full reports and dashboards through a web interface.
  • Notifies reporters and integrates with TheHive, MISP, LDAP/OIDC, Elasticsearch, RustFS (S3), and ChromaDB.

Where to start