Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
AI-generated phishing emails (opens in new tab) read clean. They are very (opens in new tab) convincing (opens in new tab) and contextual enough to weaken the content signals message scoring was built on, moving detection value to the infrastructure behind them.
AI phishing detection with threat intelligence ties a lure to the domains and sender accounts behind it, then connects it to multi-channel activity (opens in new tab), so a fluent message carrying no known-bad indicator still gets caught. That intelligence usually reaches the detection layer and the takedown queue, and then the campaign closes as a ticket.
Then the pretext comes back. The domain is dead and the sending account is gone, but the same story arrives next month by text message (opens in new tab), phone call (opens in new tab), or meeting invitation (opens in new tab). Once the attack leaves the inbox, a rehearsed employee is the control that remains.
A confirmed detection hardens defenses and drives takedown. It can also hand the awareness program (opens in new tab) a live pretext to rehearse, the destination that rarely has an owner.
Treat a confirmed detection as intelligence with more than one consumer.
Disruption and rehearsal run off the same campaign intelligence.
AI phishing detection grounded in threat intelligence produces three things a tool that scores the message alone cannot: the infrastructure behind the lure, the pretext and the channels carrying it, and the action the campaign asks its target to take.
Generative AI (opens in new tab) removed the language errors and reused templates message-level scoring once matched, so the durable signals became campaign infrastructure and account behavior, which external threat intelligence (opens in new tab) supplies.
A confirmed detection is an intelligence product with several outputs, and they do not all have a destination.
An email threat intelligence (opens in new tab) program produces confirmed detections, and each has three consumers: it hardens detection against the next variant, it drives a takedown of the campaign's infrastructure, and it becomes rehearsal material for the people the campaign was built for.
The first two are settled: hardening is automatic, and takedown is a mature capability someone owns. What rarely exists is a route to the awareness program, or an owner for it.
Taking down a campaign's infrastructure does not retire its pretext. The story that worked once gets rebuilt on infrastructure that does not exist yet and arrives on a channel with no filter in front of it. That is why a confirmed detection is worth more as rehearsal material than as a closed ticket.
Hardening turns one caught campaign into a rule for the next. Every confirmed campaign enriches campaign-level correlation (opens in new tab), so the next variant matches on what it shares with the last one: registrant patterns, phishing-kit behavior, and indicators the campaign already burned.
Takedown removes what the attacker built. Registrars pull the domains, providers suspend the sending accounts, and cloned pages (opens in new tab) lose their hosting. That changes attacker economics, and operators respond by moving delivery to channels the takedown did not touch.
Rehearsal is the consumer with no owner, and the verdict's intelligence already describes the story, the borrowed identity, and the requested action the attacker reuses. Scattered Spider's help-desk social engineering (opens in new tab) has persisted as its TTPs evolve: the group poses as an employee calling IT for a password or MFA reset (opens in new tab), over voice and SMS as readily as email.
An employee who has faced that request carries recognition a filter cannot supply, and their response updates the risk profile that aims the next round.
Reusing a caught email as a template throws away the most valuable part. A campaign that opened by text and escalated to a cloned voice (opens in new tab) becomes an email with a suspicious link, drilling a channel the attackers never used.
Turning a detection into a rehearsal takes three things: choosing the detections worth rehearsing, reproducing the pretext on the channel it will arrive on next, and running it in days without contaminating the reporting queue.
Program design and measurement belong to the awareness program (opens in new tab).
A high-volume stack confirms more campaigns in a week than an awareness team can rehearse, so a selection rule keeps the rehearsal tailored to real threats (opens in new tab). Prioritize a detection whose pretext the workforce has not been asked before, that targets a role with a transaction path (payments, credentials, access provisioning, customer data), and that arrived on an undrilled channel.
Start with the detections that meet all three, because they describe a request employees will face with no reflex behind it, then work down to two.
Fidelity means the story, the borrowed identity, and the requested action, delivered on a channel the campaign has already used and the program has not drilled.
If the campaign asked a help-desk agent (opens in new tab) to reset MFA by phone, the phishing simulation (opens in new tab) has to put a voice on the phone asking for that reset.
Launch within days of the verdict, faster than a content cycle that treats annual awareness training (opens in new tab) as its baseline. Speed carries a risk: a live pretext fired at the workforce mid-campaign puts genuine reports and simulated ones in one queue.
Three guardrails handle it: tag simulated messages so the security operations team can filter them, exclude anyone the live campaign already reached, and tell whoever owns the reporting queue (opens in new tab) before launch.
An organization's human risk management (opens in new tab) data is intelligence too, and intersecting it with campaign intelligence decides who rehearses what. Campaign intelligence answers what people are about to be asked. Risk data answers who has already struggled with that ask, and on which channel.
Exposure means the roles a campaign's pretext and requested action put in reach, not seniority or job title. Any program already running simulations has the data to aim the first rehearsal.
A profile shows where a person is thin by recording what they did under test: click rate, data submission rate, response speed, a consecutive-fail streak, and quiz results.
Data submission rate shows who completed the action an attacker needs, and the per-channel breakdown (opens in new tab) shows where that number collapses, since a person careful on email may submit over SMS.
Exposure and susceptibility rarely name the same people, and the overlap is where a rehearsal starts. Say a vendor-invoice pretext (opens in new tab) arrives by text. It exposes accounts payable and procurement, the roles that approve exactly that payment.
The per-channel breakdown inside those teams shows who has submitted data outside email under test. Start with that intersection, then reach the remainder, whose profiles say nothing about messaging channels. The output is a named audience and a channel assignment.
The outcome determines what each person gets next, and it has to be the action the campaign asked for. A rehearsal built from a wire-transfer pretext and scored only on whether someone engaged measured the wrong thing, because the loss event is the approval.
Moving beyond click rates (opens in new tab) means grading that. Then split the follow-up: whoever submitted credentials gets the verification-step module for that request, engagement short of submission gets a shorter reinforcement, and a report gets a record that the reflex worked.
Doppel runs both directions of this loop on one intelligence layer. It is an AI-native Social Engineering Defense (SED) (opens in new tab) platform that unifies Digital Risk Protection (opens in new tab), Human Risk Management, and Email Security.
Outward, the Doppel Threat Graph correlates domains, social accounts, paid ads (opens in new tab), telco activity, and dark web signals into campaign-level views (opens in new tab). AI agents run detection and correlation, then execute takedowns while analysts handle novel escalations. Doppel Email Security (opens in new tab) applies the same intelligence to the inbox, so the sending infrastructure and malicious links behind a phish come down with the message.
Paired with Digital Risk Protection, the disruption reaches the rest of the campaign, including lookalike domains and fake profiles.
Inward, Doppel converts a detected threat into an employee simulation in one click, and Doppel Simulation (opens in new tab) delivers it across email, voice, SMS, Microsoft Teams and Zoom meetings, and Telegram. Vibe phishing (opens in new tab) builds the message and landing page from a natural-language prompt, so the rehearsal carries the pretext itself.
Voice simulations run as live conversations that adapt to what the target says, and a campaign can chain multi-channel follow-ups in real time, the way attackers do when a target pushes back. Per-channel reporting and per-user risk reports turn those responses into the profile that routes each person's next assignment through Human Risk Management (opens in new tab).
Assign an owner to decide where a confirmed detection goes after the verdict. Hardening and takedown already have answers, and both point back at the attacker's infrastructure. The pretext survives them.
The second destination is the workforce, and the intelligence that hardened the filter is the best available description of what they will be asked next. The campaign your team dismantles externally becomes the campaign your workforce rehearses, aimed by your own risk data.
Request a demo (opens in new tab) to see the loop run against a threat targeting your brand.
It catches campaigns whose messages are clean. The verdict comes from the domains and sending accounts behind the lure and the campaign's activity on other channels, and the same intelligence names the pretext and the requested action: what to dismantle, and what employees need to rehearse.
Give it to whoever runs the awareness program, with a fixed cadence and a standing feed from the detection queue. Without a named owner, confirmed detections close as tickets and their training value expires with the takedown. That owner picks which detections become rehearsals and which audience receives them.
BLOG
Our graph-driven platform is built to collapse fragmented signals into a single, real-time view of active campaigns. Instead of surfacing thousands of unrelated alerts, our threat graph links domains, accounts, phone numbers, ads, and wallets into connected infrastructure maps.
by Doppel Team