Salesforce scales user-reported phishing analysis with Intezer

Salesforce runs one of the largest CSIRT operations in the world, and its employees report a constant stream of suspicious emails. Manually triaging that volume was slowing the team down and burying analysts in repetitive work. By routing reported emails through Intezer AI SOC for automated analysis, the CSIRT team now resolves the people-reporting side of phishing almost entirely through automation, contains real threats faster, and has freed its tier-one analysts to focus on proactive security activities including tuning rules with the threat detection team and more.

A global automation function

Matan Ziv is a leading incident responder in Salesforce’s CSIRT. His role is horizontal, in the sense that he works closely with both the automation team and the broader CSIRT organization, bringing together a global threat detection team and a regionally distributed SOC.

Among his many projects, Matan builds SOC-related automations. Tools like Intezer fall within his domain precisely because of that work, which spans Salesforce's CSIRT groups worldwide.

"Intezer is well integrated into our SOC team’s daily workflows. It’s all automated. Our analysts now have time for more proactive security."
Matan Ziv
Lead Incident Responder - CSIRT at Salesforce
Matan Ziv

The challenge

For a company of Salesforce's size, employee-reported email is a firehose. People flag suspicious messages two ways, through an add-on or button inside Google Workspace, and by forwarding messages to a shared security inbox. Even a modest reporting rate produces enormous numbers.

As Matan put it, even if only a fraction of employees report a message, the totals are still very large. The core problem was twofold, the sheer volume of reported emails and the time it took to investigate each one.

That delay carried real risk. A single phishing message can land in thousands of inboxes, and it only takes one person to click. When a report sat in a queue for a day or two, any malicious action triggered by a click was already underway by the time an analyst got to it.

The solution

Intezer handles the analysis of employee-reported suspicious emails, which Matan described as the precise problem it solves for the team. It sits specifically on the people-reporting side of phishing, complementing the detection platforms Salesforce already runs, such as Proofpoint, on the gateway side.

The workflow is layered and heavily automated. Reported messages first pass through internal classification agents built on Agentforce. Those agents sort out reports that are not security relevant, such as infrastructure questions or physical-security matters at specific buildings, so they never need analysis. Anything identified as a suspicious or phishing report flows into Intezer.

Messages containing sensitive or customer-related information are excluded from this flow by policy, with legal-approved exceptions kept out of the pipeline. Beyond those exceptions, nearly every reported email gets analyzed.

How it works

Once Intezer returns a verdict, Salesforce's own agents take over the response.

For legitimate emails, the process runs without any analyst involvement. An agent processes the verdict and replies to the reporting employee to let them know the message is safe. Because multiple people often report the same email, Intezer deduplicates and processes those reports automatically, so no one has to copy and paste responses across duplicate tickets.

For malicious emails, human analysts step in, but with a running start. An agent extracts the indicators of compromise from the Intezer report and adds context, so analysts are not handed a raw report and told to work through the whole thing themselves. Pulling and removing malicious messages from inboxes is part of this automated handling as well.

Matan summarized the division of labor simply. The analysis belongs to Intezer, and the response actions belong to Salesforce's agents and analysts. He described the integration as well embedded in the team's daily workflows, with everything surfaced inside the Salesforce platform so people can read a report if they want to but rarely need to.

Results

  • Faster containment, lower impact. Matan was clear that the biggest difference is time. Whether or not a threat would have been missed outright, the consequences of a slow response are far worse at Salesforce's scale. Acting in minutes rather than days means a clicked link can be contained before the damage spreads. One click out of a hundred recipients, or one out of ten thousand, is enough to matter.
  • Analysts redirected to higher-value work. The tier-one analysts who once worked through every reported email now have time and mental bandwidth for proactive work. They focus on tuning and on supporting the threat detection team, which ships new detections on a daily or weekly cadence.
  • A feedback loop with threat detection. With queues no longer overwhelming, analysts now flag noisy or repetitive detections to the threat detection team instead of closing tickets and moving on. Matan described this as a snowball. When an analyst suggests a tuning change or an automation and sees it implemented, it boosts morale and prompts more suggestions, which spread across the team and compound over time.
  • Improved morale and reduced burnout. Matan pointed to a clear positive effect on morale and burnout, driven in large part by removing repetitive duplicate-report handling. He also noted that value showed up quickly after deployment, and that the support experience with the Intezer team has been responsive and easy to work with.
100%
of all alerts are investigated using proven forensic capabilities combined with agentic AI reasoning
<2%
of all alerts are escalated for human review with the rest automatically resolved
<1
minute for full triage on all alerts

To learn more about Intezer AI SOC, schedule some time with our team.

More customer stories

Case Study

3 min read

Salesforce scales user-reported phishing analysis with Intezer

Salesforce runs one of the world's largest CSIRT operations, where manually triaging a constant flood of employee-reported suspicious emails was slowing down the team. With Intezer AI SOC the team now handles phishing reports almost entirely through automation, contains real threats faster, and has freed tier-one analysts for proactive work like tuning detection rules.

Case Study

1 min read

Executive interview with the CTO of MGM Resorts International

We’re honored to have Branden Newman, CTO of MGM Resorts International, on Intezer’s Customer Advisory Board.

Case Study

3 min read

DPD automates SOC tier-1 tasks with Intezer

With a lean security team, DPD Poland uses Intezer to automate triage, investigation, and remediation of endpoint security alerts, keeping the company more secure while saving them over 2,500 hours.

Contact us

Ready to see for yourself?

For more information around security and compliance, please contact us