Skip to main content
Cybersecurity Awareness Month: New videos, games, and ready-to-use resources

Most security teams already run their day out of a central system. Alerts land in a SIEM, response runs through a SOAR, and work gets tracked in a ticketing tool. When email threats live in a separate console, analysts end up checking one more screen and copying sender, subject, and verdict details into tickets by hand before they can act.

Today, we're launching Email Security Webhooks and REST API, which connects Adaptive Email Security to your SIEM, SOAR, or ticketing tools so detections and remediations flow directly into your existing security workflows.

What's in Webhooks and REST API

The release works in two directions. Adaptive tells your system what happened, and your system tells Adaptive what to do.

Webhooks send a new alert to your system once Adaptive finishes analyzing an email. Each alert includes the email details, Adaptive's analysis, and the initial remediation state, so your tools get the full picture without anyone opening another console.

You control which alerts flow out by filtering on three dimensions.

  • Classification sends Malicious alerts, Spam alerts, or both.
  • Review status sends only the events that need a human decision, or every analyzed event.
  • Source narrows alerts to Detection, User Report, Similar Fetch, or Denylist.

The REST API lets your SOAR, ticketing tool, or custom automation work with those events directly.

  • Get current details pulls the latest email details, analysis, related messages, and remediation status for any event.
  • Take action quarantines an email, moves it to spam or trash, or marks it safe or spam. Move actions can also cover existing and future similar messages.
  • Undo remediation restores the emails moved for an event.
  • Manage rules lets you view, add, and remove Adaptive allowlist and blocklist rules.

Why It Matters

Email threats now get handled where the rest of your security work already happens. Analysts no longer need to watch the Adaptive console for every alert or rebuild email details in a ticket by hand. The alert arrives with the email details, the analysis, and the remediation state already attached.

That turns a multi-step manual handoff into a single automated flow. A malicious email can be detected by Adaptive, routed into your SIEM, picked up by a SOAR playbook, and quarantined along with its similar messages without anyone switching tools. When an analyst needs more context, the API returns the latest analysis and remediation status on demand.

It also covers a requirement most enterprise security teams bring to every email security evaluation. Alerts go into the systems you already use, and response can be automated end to end.

How It Fits Into Your Existing Workflow

Nothing about how your team works has to change. You point Adaptive at an endpoint you control, whether that's Splunk, Sumo Logic, Tines, ServiceNow, or your own middleware, and build the workflow the way your SOC already runs.

Teams logging everything for visibility can stream every analyzed event into their SIEM. Teams focused on response can send Needs Review alerts into a ticket queue and let analysts close them out from there. Teams with mature automation can let SOAR playbooks act on Malicious verdicts directly, and the same playbook can undo a remediation if a call needs to be reversed.

Allowlist and blocklist rules can be managed from that same automation, so the policy decisions your SOC makes stay in sync with Adaptive.

Available Now

Webhooks and the REST API for Adaptive Email Security are live today. Full details on supported events, filters, and actions are available in the Adaptive developer documentation. If you'd like a personalized walkthrough of the Adaptive Security suite of products, including Agentic Email Security, book a demo today.

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Human and Agent Security for the AI Era.