
Co-founder & CCO

LimaCharlie Email Security is generally available today. It protects Microsoft 365 and Google Workspace mailboxes from inside the same tenant, permission model, and data lake as the rest of LimaCharlie. A phishing email and the endpoint activity it causes can now be detected, investigated, and remediated in one place.
A phishing email is often the first step in an intrusion, yet in most stacks email security runs as a separate product with its own console. The email tool can tell you a message was malicious. It usually can't tell you whether the recipient opened the attachment, whether that attachment executed, or which systems the compromised account can reach. Answering those questions means exporting alerts, switching consoles, and correlating by hand. For MSSPs, that work repeats for every client.
"Emails are events in a way. You want to do correlation, you want to do alerting, you want to do response on it."
Maxime Lamothe-Brassard, founder and CEO, LimaCharlie
That idea shapes the whole product. Every message LimaCharlie ingests is parsed, judged, and written to the same lake as your EDR, cloud, and identity telemetry. A detection like "a phish was delivered, then the recipient's endpoint ran a new binary" is a single detection and pivot in a single place. From there, an analyst or an AI agent can pivot from the message to the endpoint to the cloud resources that user can access, without leaving the platform.
The same lookups and YARA rules work on both sides. A phishing-domain feed synced daily from GitHub can flag an inbound message and the endpoint DNS request that follows it, and attachments are scanned with the same YARA rules your endpoints use.
Connect through the provider API
Add a Microsoft 365 or Google Workspace tenant with an API credential. MX records and mail routing stay exactly as they are. A connection test checks every permission the collector needs and reports each one individually. Up to 14 days of historical mail is then judged with the same rules as live traffic, so the queue fills with real verdicts shortly after you connect.
Get an explainable verdict on every message
Each message receives one verdict: malicious, suspicious, graymail, or benign. Verdicts come from a weighted managed rule pack plus any rules you write. Enrichment covers sender and domain history, VIP and lookalike-domain impersonation, domain registration age, link features, and attachment explosion, including recursive archive unpacking, macro extraction, and QR code decoding. Attachments are unpacked recursively through Strelka and scanned with your own YARA rules. Every non-benign verdict shows the signals that produced it and the weight of each.
Remediate with a full audit trail
Quarantine, trash, move to spam, restore, or apply a warning banner at the provider. You can trigger each action from policy, the console, a D&R rule, the API, or the CLI, and every action is audited. Policy ships in alert-only mode, so nothing moves until you switch to enforce.
Triage campaigns once
Messages from a single attack are clustered into a campaign, so a phish that hit forty mailboxes is triaged once and swept once. The abuse mailbox becomes an SLA queue, with each user report joined back to the original message across the tenant.
Run AI triage on your own terms
AI triage is a standard LimaCharlie AI agent running on the model and provider you choose. It starts from a reviewed reference agent that you can edit or replace. Because you choose the model and provider, you decide where message data is processed, which matters for customers with data residency requirements. The agent's API key decides whether it can act. If a passive agent tries to move mail, the request is refused server-side and the attempt is audited.
Manage everything as code
Connections, policy, and custom rules are stored as Hive records. Your email security configuration is API-first and syncs to git like the rest of your LimaCharlie deployment.
For MSSPs and MDR providers, each client's mail tenant runs as its own LimaCharlie org, with its own policy, permissions, and audit trail. Package a baseline of connections, policy, and rules as code and deploy it to every client org. Email security arrives on the same platform and bill as the endpoint and cloud coverage you already deliver. At $1 per mailbox per month, an MSSP can price email security into a managed service with room for margin and cover every client mailbox on one bill.
Because email carries more sensitive information than most telemetry, access is split into separate permissions. Viewing the queue and the parsed message is one permission. Remediating live mail is another. Downloading a message's original bytes requires its own permission plus a logged justification.
Email Security analyzes each message as soon as the provider's API makes it available. It works behind Exchange Online Protection, Defender, or Gmail's own filtering and judges what those filters let through. Remediation removes a message from the inbox after it lands.
Email Security is available now for Microsoft 365 and Google Workspace at $1 per mailbox per month, billed through your existing LimaCharlie account. Attachment analysis, the built-in rule pack, and your own D&R rules, YARA rules, and lookups are included in that price. AI triage runs on your own model provider, and each agent carries a per-run budget ceiling.
Emails Are Events: The Live Launch of LimaCharlie Email Security
On October 14, Maxime Lamothe-Brassard, founder and CEO, gives the first public demo of Email Security. He'll connect a live tenant, sweep a campaign, and follow a phish from the inbox to the endpoint. [Register here]
Integrated Email Security with LimaCharlie: Hands-On Workshop for MSSPs
On October 28, Sr. Solutions Engineer Ken Westin leads a hands-on session for service providers. Participants connect a live mail tenant, write custom signal and correlation rules, integrate IOC feeds, and manage configurations as code for reuse across client orgs. [Register here]