Suspicious¶
AI-powered phishing & threat-analysis platform built by Thales Group CERT. Suspicious automatically inspects, classifies, and reports suspicious emails, files, URLs, IPs, and file hashes.
What it does¶
- Analyzes suspicious content: emails, documents, URLs, IPs, and file hashes.
- Runs deep analysis pipelines: YARA rules, sandboxing, metadata inspection, an AI email classifier, and Cortex analyzers.
- Classifies results as Safe, Inconclusive, Suspicious, or Dangerous.
- Provides full reports and dashboards through a web interface.
- Notifies reporters and integrates with TheHive, MISP, LDAP/OIDC, Elasticsearch, RustFS (S3), and ChromaDB.
Where to start¶
- Run it: Getting Started
- Use it: User Guide
- Understand it: Architecture
- Hack on it: Components and Contributing
- Integrate: API Reference