Release candidate · deployment validation required

Email Investigation Workspace

Investigate suspicious emails.
Keep the evidence.
Connect the dots.

One focused workspace for security teams. Turn suspicious messages into documented investigations — with the evidence, context and human decisions kept together.

Cloud preparation · signup is closed

PhishCase / workspace
CASE #042 · INVESTIGATING

Invoice review · payment request

message.eml · SHA-256 · Evidence preserved
Automated: suspiciousAnalyst decision: pending
Senderbilling[@]example[.]invalid
Reply-Toaccounts[@]alternate[.]invalid
URLhxxps://example[.]invalid/invoice
Evidence073a814c7062…90654ad76a6
A conclusion you can explainRecord a verdict, confidence and rationale. Keep every change.
Product illustration · synthetic data
Open-source coreOffline by defaultEML + MSGYour keys, your policy

From the first signal to the final decision

A connected investigation.
A clear next step.

Spend less time moving between tools. Keep the original message, findings and analyst work in one place.

01 /

Email

Upload one message or a batch of EML and MSG files. The original becomes your evidence.

02 /

Analysis

Extract headers, bodies, attachments and indicators. Durable jobs continue after you close the tab.

03 /

Enrichment

Look up reputation with your own keys. Submission is a separate, explicit permission.

04 /

Correlation

Find shared URLs, hashes and senders across past investigations. Group related cases into campaigns.

05 /

Decision

Separate automated findings from your conclusion. Record the rationale, export the report and close the case.

Community · open source

Your investigation.
Your infrastructure.

Community is a complete single-team workspace. Run it with Docker, keep it offline, and enable external providers only when your policy allows.

View on GitHub ↗
  • EML / MSG and batch upload
  • Cases, notes and timeline
  • Indicators and campaigns
  • Analyst decisions and exports
  • Roles and TOTP MFA
  • BYOK enrichment and API
Start from the public repositorygit clone --branch feature/release-candidate-v1 https://github.com/CybersecSpirit/phishcase.git
cd phishcase
git checkout 1eaf0323ce0f4986a28e78dd066a609321f98d6f
docker compose up -d --build

Read the installation guide →

Designed around evidence

Control what leaves.
Know what stays.

Practical safeguards for suspicious content. Clear boundaries between local analysis, external lookups and evidence submission.

Evidence first

Original message bytes are preserved with their SHA-256. Notes, labels and analyst decisions do not change the original.

No silent submission

Offline mode makes no external calls. Restricted mode permits lookups only. File or URL submission requires policy permission and an explicit action.

Human judgment matters

A missing detection is not a safety verdict. Automated signals and the analyst conclusion stay separate, with a traceable decision history.

Choose how you operate

Start with Community.
Grow on your terms.

Self-host one team, move to Cloud, or operate Enterprise on your own infrastructure. Provider keys and licenses remain yours.

Community

A useful open-source workspace.

€0
Your infrastructure, your capacity
  • Open source · MIT core
  • Self-hosted · Docker · one team
  • EML / MSG · cases · IOCs
  • MFA · campaigns · reports
  • BYOK · API · offline
Deploy Community ↗

Cloud Starter

For a focused investigation team.

€49 / month
14-day trial · 30 analyses · no credit card
  • 3 analysts
  • 500 analyses / month
  • 90 days retention
  • EML / MSG uploads
  • BYOK enrichments
  • Campaigns and reports
  • Ingestion API
  • Standard support
Cloud availability ↗

Cloud Business

For structured security programs.

€349 / month
14-day trial · 30 analyses · no credit card
  • 25 analysts
  • 10,000 analyses / month
  • 365 days retention
  • Full API and policies
  • Advanced audit*
  • SSO*
  • Priority support
Cloud availability ↗

Enterprise On-Premise

From €7,500 / year

Docker on your infrastructure, offline operation and enterprise integration options. SSO/LDAP and advanced connectors follow the validation milestones.*

Installation, migration, SIEM/SOAR integration, training and enhanced support are scoped separately.

Contact us ↗

Future offer

MSSP

Multi-client operations, delegated access, client quotas, branding and reporting. A future offer shaped with service providers.

Contact us ↗
Commercial offer specification. Cloud activation follows deployment validation. Items marked * are planned rollout capabilities, not claims of availability.

Prices are configured centrally. Provider subscriptions and licensing are separate. No commercial rights are implied by a free VirusTotal key.

Clear scope. Clear expectations.

Built for investigators,
not email delivery.

Does PhishCase replace an email gateway?

No. PhishCase is a phishing investigation workspace for SOC, CERT and security teams. It complements mail protection and centralizes the investigation after a suspicious message is reported.

Can Community work entirely offline?

Yes. Local analysis, original evidence, cases, notes, indicators and human conclusions remain available without external providers. Build and dependency downloads require network access unless images and dependencies are prepared in advance.

Is any email sent to VirusTotal automatically?

No. Reputation lookup and submission are distinct operations. The administrator controls which providers and operations are allowed. A file or URL submission is explicit; VirusTotal standard APIs do not guarantee private handling.

What is open source?

The Community investigation core is public under MIT, preserving attribution to eml_analyzer and Manabu Niseki. Commercial organization, billing and operating capabilities live in a separate private Enterprise repository.

Can people report emails from Outlook or Gmail?

The first release supports EML/MSG uploads, batch uploads and authenticated ingestion API. Inbound mailboxes and Outlook/Gmail add-ins are future roadmap items.

Make every investigation count.

Begin with your evidence. Keep your decisions. Build on what your team already knows.