Detection

Threats: automatic mailbox sweeps and AI verdicts

How the 15-minute sweep works, how to read an AI verdict, and how to use the AI Threat Analyst chat.

9 min read
Email envelope protected by an AI-driven security shield

How the automatic sweep works

Every 15 minutes RadarX walks each connected tenant, then each mailbox (oldest-swept first), and pulls new inbox messages through Microsoft Graph or Gmail. Messages are stored de-duplicated, so a message is only ever scored once.

Each run is bounded (25 mailboxes, 15 messages per mailbox) and protected by a single-flight lease, so overlapping runs cannot double-process a tenant. Progress is saved per mailbox, so the next run picks up exactly where the last one stopped.

Running a sweep on demand

Useful right after onboarding a tenant or when a client reports an email in progress.

  1. 1Open Threats.
  2. 2Click Sweep mailboxes now in the page header.
  3. 3Watch the status banner. It reports how many mailboxes were visited, how many new messages were ingested, and any provider errors.

Reading a verdict

Every scored message gets one of four verdicts: clean, suspicious, malicious, or unknown when the provider data was incomplete.

Open a threat to see the AI's key findings, sender analysis (domain age, authentication results, reply-to mismatch, lookalike domains), content analysis (urgency, payment or credential requests, tone matching known BEC patterns) and extracted indicators such as URLs, attachment hashes and sending IPs.

Suspicious verdicts automatically raise a medium alert; malicious verdicts raise a critical alert. Clean verdicts are stored for evidence but do not alert.

Submitting a message manually

When a user forwards you a suspect email, you can score it without waiting for a sweep.

  1. 1In Threats, choose Analyse message.
  2. 2Paste the sender, subject, and the message body or raw headers.
  3. 3Submit. The AI verdict appears within a few seconds and is stored against the tenant.

AI Threat Analyst chat

Open any threat and use the chat panel to interrogate the finding in plain language: ask why it was scored the way it was, what the indicators mean, what you should tell the client, or which containment steps apply. The analyst answers with the full context of that message and the tenant's recent history.