Use Case

Email Security

ARIA ingests Google Workspace Alert Center signals, investigates phishing and business email compromise attempts in context, and escalates confirmed threats for security engineer review.

Gmail Alert Center Phishing BEC Spam Classification Google Workspace

Where the Signal Comes From

ARIA's email monitoring is built on top of Google Workspace Alert Center, the native security alert feed that Google produces for Workspace administrators. Alert Center fires when Google's own detection systems identify a phishing attempt, a malware attachment, a suspicious login linked to an email account, or a government-backed attack warning. ARIA subscribes to this feed via a service account with read access to the tenant's Alert Center and Admin SDK logs.

This means ARIA's email visibility is scoped to what Google exposes: it does not independently scan the body or attachments of every message. What it adds is investigation depth — pulling account activity context, correlating with other signals from the same tenant, and making a triaged finding out of a raw Google alert that would otherwise sit in an admin console few employees monitor.

For Microsoft 365 tenants, equivalent alerting is available through Microsoft Defender for Office 365 and the M365 Security & Compliance Center, though the specific event types and coverage differ from Google Workspace Alert Center.

Phishing Detection

When Google identifies a phishing message delivered to an inbox — or blocked before delivery — Alert Center fires an event that includes the sender, recipients, message ID, and Google's classification. ARIA receives that event and enriches it:

  • Checks whether the sender domain is newly registered, on an external blocklist, or has been seen in prior alerts for this tenant
  • Looks up any links in the alert metadata against threat intelligence
  • Reviews whether the targeted user has clicked or replied (visible in Gmail API activity metadata, not message content)
  • Checks for related activity on the same account — signs of a broader campaign or account compromise in progress

If the alert is a confirmed threat — malicious sender, known phishing infrastructure, evidence of user interaction — it escalates to a security engineer with the full investigation context. If the enrichment shows the alert is a false positive or a low-risk marketing email, ARIA closes it automatically with a recorded rationale.

Business Email Compromise

Business email compromise (BEC) is the most financially damaging email threat category for organizations that don't carry cyber insurance with dedicated BEC riders. Unlike phishing, BEC rarely uses malicious links or attachments — it relies on impersonation and social engineering. The message looks legitimate. Google's classifier often doesn't flag it.

ARIA detects BEC precursors and patterns through identity and email metadata signals:

Account Takeover Precursor

A login from an unfamiliar IP or device combined with immediate inbox rule creation — forwarding all mail to an external address — is a strong indicator of account compromise being used for BEC. ARIA correlates these events across the Workspace Admin SDK and Gmail activity logs.

Display Name Spoofing

Alert Center fires on outbound mail where the sender's display name matches an executive but the sending address does not match the domain. ARIA investigates whether the account sending the message has any prior relationship with the recipient or any legitimizing activity in the tenant history.

Forwarding Rule Anomaly

New mail forwarding rules created by a user — especially rules that silently copy all inbound mail to an external address — are surfaced by the Admin SDK activity log. ARIA flags these because they are a reliable indicator of either an account compromise or an insider moving mail outside the organization's visibility.

Spam Classification

Alert Center includes signals on spam campaigns that reach Workspace inboxes despite Google's filters. ARIA logs these events and provides context on campaign scope — whether the same campaign hit multiple users in the tenant, whether the sending infrastructure is associated with known credential harvesting operations, and whether any user has interacted with the messages.

Spam alerts rarely escalate. Most are confirmed low-risk and closed automatically. The value is in the audit trail: a documented record of what reached the environment, when, and what ARIA determined.

What ARIA Does Not Do

ARIA does not scan the full body or attachments of messages for sensitive content patterns — it has no data loss prevention capability in email. Message content access is limited to metadata surfaces exposed by the Gmail API and Alert Center. This is an intentional scope constraint: content inspection raises significant privacy considerations and is out of scope for the current platform.

ARIA also does not modify email routing, quarantine messages, or block senders automatically. Any containment action — revoking a compromised account's sessions, removing an inbox rule — is proposed by ARIA and executed only after a security engineer approves it.

Common Questions
Does ARIA read our email content?
No. ARIA's access is limited to alert metadata from Google Workspace Alert Center and activity metadata from the Gmail API and Admin SDK — sender, recipient, timestamp, subject line (in some alert types), message ID, and user interaction signals (whether a message was opened or a link clicked, not what the link was or what the message body contained). ARIA does not have access to message body content or attachment contents, and it does not scan inbound or outbound mail independently of what Google's Alert Center surfaces.
What happens when ARIA confirms a phishing attempt?
ARIA escalates the finding with its full investigation context — what triggered the alert, what enrichment it performed, what it found, and what it recommends. A security engineer reviews the escalation and approves any action. Possible actions include revoking the targeted user's active sessions, forcing a password reset, removing the message from other inboxes if it spread internally, or adding the sender to a blocklist. None of these run automatically; they require the engineer's explicit approval on each step.
Does this work with Microsoft 365?
Microsoft 365 alerting is available through ARIA's M365 integration, which subscribes to Microsoft Defender for Office 365 alert signals and the M365 Security & Compliance Center. The specific event types, alert fidelity, and API coverage differ from Google Workspace Alert Center — Google Workspace is the more fully characterized integration at this time. Contact us to discuss M365 coverage specifics for your environment.
Can ARIA detect when someone inside the company is forwarding mail externally?
Yes. The Google Workspace Admin SDK activity log records when a user creates or modifies inbox rules, including forwarding rules. ARIA monitors for the creation of forwarding rules that send to external addresses — a pattern associated with both account compromise and insider data movement. The detection triggers on rule creation, not after mail has been forwarded, giving a security engineer the opportunity to investigate before significant data has left the environment.

See Email Security in Your Environment

A 30-minute call, a read-only ARIA agent connected to your Google Workspace tenant, and a findings report within 48 hours — including open Alert Center findings ARIA would have triaged.

Book Free Assessment
No contract. No setup fee. Cancel anytime.

More Use Cases

ARIA monitors identity, endpoints, and cloud activity alongside email — the same triage pipeline handles all four.

View All Use Cases