Upload one message or a batch of EML and MSG files. The original becomes your evidence.
Email Investigation Workspace
Investigate suspicious emails.
Keep the evidence.
Connect the dots.
One focused workspace for security teams. Turn suspicious messages into documented investigations — with the evidence, context and human decisions kept together.
Cloud preparation · signup is closed
Invoice review · payment request
hxxps://example[.]invalid/invoice073a814c7062…90654ad76a6From the first signal to the final decision
A connected investigation.
A clear next step.
Spend less time moving between tools. Keep the original message, findings and analyst work in one place.
Analysis
Extract headers, bodies, attachments and indicators. Durable jobs continue after you close the tab.
Enrichment
Look up reputation with your own keys. Submission is a separate, explicit permission.
Correlation
Find shared URLs, hashes and senders across past investigations. Group related cases into campaigns.
Decision
Separate automated findings from your conclusion. Record the rationale, export the report and close the case.
Community · open source
Your investigation.
Your infrastructure.
Community is a complete single-team workspace. Run it with Docker, keep it offline, and enable external providers only when your policy allows.
View on GitHub ↗- EML / MSG and batch upload
- Cases, notes and timeline
- Indicators and campaigns
- Analyst decisions and exports
- Roles and TOTP MFA
- BYOK enrichment and API
git clone --branch feature/release-candidate-v1 https://github.com/CybersecSpirit/phishcase.git
cd phishcase
git checkout 1eaf0323ce0f4986a28e78dd066a609321f98d6f
docker compose up -d --buildDesigned around evidence
Control what leaves.
Know what stays.
Practical safeguards for suspicious content. Clear boundaries between local analysis, external lookups and evidence submission.
Evidence first
Original message bytes are preserved with their SHA-256. Notes, labels and analyst decisions do not change the original.
No silent submission
Offline mode makes no external calls. Restricted mode permits lookups only. File or URL submission requires policy permission and an explicit action.
Human judgment matters
A missing detection is not a safety verdict. Automated signals and the analyst conclusion stay separate, with a traceable decision history.
Choose how you operate
Start with Community.
Grow on your terms.
Self-host one team, move to Cloud, or operate Enterprise on your own infrastructure. Provider keys and licenses remain yours.
Community
A useful open-source workspace.
- Open source · MIT core
- Self-hosted · Docker · one team
- EML / MSG · cases · IOCs
- MFA · campaigns · reports
- BYOK · API · offline
Cloud Starter
For a focused investigation team.
- 3 analysts
- 500 analyses / month
- 90 days retention
- EML / MSG uploads
- BYOK enrichments
- Campaigns and reports
- Ingestion API
- Standard support
Cloud Team
For a growing security operation.
- 10 analysts
- 3,000 analyses / month
- 180 days retention
- Full API
- Campaign and correlation workflows
- Advanced reports and webhooks*
- Standard support
Cloud Business
For structured security programs.
- 25 analysts
- 10,000 analyses / month
- 365 days retention
- Full API and policies
- Advanced audit*
- SSO*
- Priority support
Enterprise On-Premise
Docker on your infrastructure, offline operation and enterprise integration options. SSO/LDAP and advanced connectors follow the validation milestones.*
Installation, migration, SIEM/SOAR integration, training and enhanced support are scoped separately.
Contact us ↗Future offer
MSSP
Multi-client operations, delegated access, client quotas, branding and reporting. A future offer shaped with service providers.
Contact us ↗Prices are configured centrally. Provider subscriptions and licensing are separate. No commercial rights are implied by a free VirusTotal key.
Clear scope. Clear expectations.
Built for investigators,
not email delivery.
Does PhishCase replace an email gateway?
No. PhishCase is a phishing investigation workspace for SOC, CERT and security teams. It complements mail protection and centralizes the investigation after a suspicious message is reported.
Can Community work entirely offline?
Yes. Local analysis, original evidence, cases, notes, indicators and human conclusions remain available without external providers. Build and dependency downloads require network access unless images and dependencies are prepared in advance.
Is any email sent to VirusTotal automatically?
No. Reputation lookup and submission are distinct operations. The administrator controls which providers and operations are allowed. A file or URL submission is explicit; VirusTotal standard APIs do not guarantee private handling.
What is open source?
The Community investigation core is public under MIT, preserving attribution to eml_analyzer and Manabu Niseki. Commercial organization, billing and operating capabilities live in a separate private Enterprise repository.
Can people report emails from Outlook or Gmail?
The first release supports EML/MSG uploads, batch uploads and authenticated ingestion API. Inbound mailboxes and Outlook/Gmail add-ins are future roadmap items.
Make every investigation count.
Begin with your evidence. Keep your decisions. Build on what your team already knows.