Security & Risk Teams
A ticket, an inbox, or a vendor form hands you an email or a domain. Search the person and the organization, and keep the case on an investigation.
The review has a report to point at. Later findings stay on the same file instead of in a thread.
Gray Harbor ops
Public sources, structured
- ops@gray-harbor.example
- Domain
- gray-harbor.example
- Also seen
- a personal mailbox on the same record
- Company claimed
- A different vendor domain
A vendor email that does not match
Accounts payable receives a payment-detail change from ops@gray-harbor.example. The vendor on file is a different domain. Search the person, then the domain in the message. The sample below is the shape of that check.
- Search 1Person
ops@gray-harbor.example
Who that mailbox is tied to in public sources.
- Search 2Company
gray-harbor.example
Whether the domain is the company they named in the email.
Filed together as Payment change — gray-harbor
How to run it
- 1
Search the external person
Use the email, phone, or profile URL from the ticket. The report is the public record attached to that identifier.
- 2
Search the domain they claim
A company domain uses company search. A school domain uses school search. Compare that record with the organization your team already trusts.
- 3
Keep the case
Add the subjects to an investigation so the next analyst opens one file, not a search history. Export a PDF for the incident notes.
- 4
Hand the report off
Zapier can send a finished report into the tools the team already watches. The API and the CLI cover the same check from a script. An agent can run it through MCP.
What you start with
- The sender's email
- A phone number from the message
- A profile URL
- The domain they claim to represent
What comes back
- The person behind the email
- Other emails and phones on that record
- Profile URLs
- The company or school on the domain
Connect it
Same search, from the tool you already have open.