Wave Wave Star illustrationStar illustrationStar illustrationMan illustrationMan illustrationGirl illustration

Hello, Welcome to Sabiki Support

Find articles, help and advice for getting the most out of your Sabiki Email Security subscription.

Frequently Asked Questions

“If you keep the small rules, you can break the big ones…”

Sabiki Email Security has been developed to provide Anti-Phishing and Anti-Spam filtering for the Microsoft 365 email ecosystem. It extends the built-in protection provided within your 365 subscription by using a next-generation AI powered Dynamic engine that is designed to organically learn and protect users from the most advanced of email attacks.

In addition to adding extra depth to 365 email security features, it can also be layered with (or replace) existing 3rd party ESGs (Email Security Gateway Solutions)

 

Sabiki Email Security is developed natively for the Microsoft 365 Email service (Outlook 365). We support Business subscriptions from ‘Microsoft 365 Business Basic’ up to and including the ‘Enterprise E5’ license.

We do not currently do not support any strictly on-premise Exchange deployment nor Google Mail services,

Yes, Sabiki Email Security is provided as a service and hosted on Azure. You are not required to ‘spin up’ any virtual machines and do not incur any infrastructure costs for your environment. It is a turn-key SaaS offering based on a per mailbox subscription.

There is no need to re-direct, re-route or change your mail flow in anyway. We simply hook in at the mailbox level utilizing the Microsoft Graph API to provide instantaneous filtering on email as the last step in the mail delivery process.

We are a Cloud native SaaS solution built on Microsoft Azure, simply authorize the Sabiki Solution during setup and then sign into the Management Portal using your Microsoft credentials.

Sabiki Email Security is a cloud based SaaS solution that is available from the Microsoft Azure Marketplace.

Once subscribed to the service and your Azure tenant is configured, Sabiki hooks into your mailflow at the mailbox level via the Microsoft Graph API and acts as the ‘last check’ for any email arriving to your end users. It will then action messages it deemed to be  ‘bad’ according to the policies set.

You do not need to re-route or re-direct your mailflow or make changes to any DNS/MX records and because of the direct integration with Microsoft Azure, all authentication is handled securely via your existing Microsoft account.

 

 

A widely accepted approach to preventing Phishing is to methodically involve users and include them in becoming part of the overall solution via user enablement and education. The various quarantine/training workflows with Sabiki Email Security allow the administrator to be as transparent or as restrictive as they need to be depending on the user’s maturity level when it comes to Phishing prevention.

When a mailbox is protected with Sabiki Email Security, a new folder is created in the user’s mail client called ‘Sabiki Phishing’ which is used as the ‘working’ folder for any message quarantine and dynamic training interaction.

The policy applied by the administrator then dictates how this folder will be used and what the user is able to do with messages.

Example:

  • During a trial, you might run in monitor mode only, meaning messages are scored and reported to the Sabiki Console, but nothing is touched or moved into this ‘Phishing’ folder
  • In production, we will allow messages above a certain scoring threshold to be automatically moved to this ‘Phishing’ folder and have any URLs/Reply-to data hidden from the user
  • For a trusted/power user, we may allow them to drag/move a quarantined message back into their inbox which will restore URLs/Reply-To data
  • We may allow the user action of moving messages in and of this phishing folder to trigger a model training cycle

By hooking in at the API level, not only does Sabiki simplify deployment and troubleshooting of mailflow in general, it provides a closer control mechanism and better analytics when performing general email administration tasks. Not to mention the revolutionary new proprietary dynamic engine that is designed to boost your phishing capture rate significantly.

During the design phase of the platform, 3 key pain points were identified for email administrators (outside of the obvious Phishing capture rate issues):

  • Sample submission

One regular task email security admins have had to deal with for current generation platforms is sample submissions of false positives/false negatives to the solution vendor. Often if there is an incident of a false negative, there is no immediate response or method of modifying the engine immediately to fix the capture issue. The mechanics of our Dynamic engine mean any false positive can immediately be trained on and the organization is not only secure against that threat, but future variations of the message too. All without submitting a sample or writing custom rules.

  • Quarantine

Our development team have tried to re-imagine quarantine for users. Quite often power users can be at a disadvantage trying to guess if an important message has been quarantined out of sight. The action of having a ‘convicted message’ moved from the user inbox to the ‘Sabiki Phishing’ folder means if power users are at a low risk level, they may simply move the message back into the inbox. For high risk users, additional controls are added where any URL/attachment/Reply-to details are stripped and can only be recovered with admin permission. Remember, Phishing is often highly targeted with the user being prompted to perform an action or reply, if we take away these risks the message itself is often redundant. A spear Phish for example would be something you certainly would not want landing in a spam digest and then being automatically released by a user.

  • Email analysis

A core pillar of the Sabiki Platform philosophy is being able to view and manipulate everything related to email security at your fingertips. Our email analysis feature will allow admins to easily and quickly review email header information and body preview messages making their daily workflows more efficient. Key security intelligence and analysis features are a priority on the Sabiki roadmap for future releases.

 

Yes, Sabiki Email security is powered by a dynamic Artificial Intelligence Engine that has been developed specifically to analyze email. The fundamental way modern Machine Learning frameworks are implemented and utilized in Cyber lend themselves to being the most efficient way to make a decision on how ‘bad’ an email is.

The difficulty in implementing them to analyze email has always been the format of the input data and generally he training dataset itself. Not only are email profiles drastically different between organizations (ie subject matter, content, theme, tone and language) but the data contained within an email can range from plain text, to HTML code, it can contain URLs and drastically different header content.

The Sabiki engine has been built from the ground up to take all of this into consideration and our unique ‘Dynamic Engine’ means we do not assume a ‘one size fits all’ model. We provide a pre-trained model that dynamically, organically grows and is tuned specifically on the email flow of your organization.

Absolutely, and you don’t need to be a Data Scientist to do so!

Over the years we have seen the struggle of email administrators investing countless hours into policy configurations, custom rule sets and constant worrying over the threat that email as an attack vector is contributing to their environment. It is clear that the application of AI to Email Security in some way, shape or form is industry standard these days, the question is how to make it as efficient, dynamic and ‘personalized’ as possible to deal with the most subtle of attacks.

During the Research and Development phase of Sabiki Email security it became clear very quickly that the instant and dynamic nature of email needed an equally dynamic and instant method of Machine Learning. We needed to remove the old workflows of sample submissions back to the vendor, rule sets and models being updated monthly, quarterly, yearly. That’s why every deployment of Sabiki Email Security is it’s own living and breathing model that will only ever increase in efficacy as it is used in production.

 

Don’t worry, we have primed the engine for you!

It would not make sense to provide a completely blank model and then expect admins to sit there for months on end trying to train it up, we have primed and pre-trained the ‘out-of-the-box’ engine with a vast data set that sees the capture rates of our customers instantly improve. It is not uncommon to see 10x improvements for heavily targeted environments or inboxes.

We could just release a model, update it once a quarter and still claim to be a robust, valuable security control on top of what customers may already have.. though the real benefit of a dynamic engine is our ability to expose the training workflow and have it trigger on user and/or admin actions.

Was there a false positive? Train on it instantly in two clicks without any sample submission or custom rules.

In the case of a false negative, train on it, ‘seek and destroy’ it instantly from all mailboxes under protection.

The method of ‘tuning’ the engine as we like to call it can be configured by the administrator. We can adopt a ‘trusted user’ method whereby certain user actions within their mail client can trigger an automatic training cycle of the model. Or we can set it to ‘admin approved’ training mode, where the admin can review the actions of their users and ‘approve’ a training cycle.

 

No.

Vendors have switched or merged their good old regular expression rule sets with newer Natural Language Processing Machine Learning models for some time now. Don’t get us wrong, NLP is powerful, but would you disregard all of that other data outside of the email body (headers for example)? The Natural ‘Language’ in the email body often makes up only 40% of the transmitted data… the proprietary Sabiki engine uses all of it in it’s decision making process.

One of the benefits of being an API base security solution is the reach that is capable at a mailbox level.

A unique feature (that came from customer feedback request) is the ability to ‘Seek and Destroy’ selected emails within all of the organization Inboxes. There may be a situation where a disgruntled employee has sent an inappropriate email, or an email with sensitive data has accidentally been sent to all employees…

The admin is able to perform a mass purge of individual emails directly from the Sabiki console in 3 clicks. Customer feedback is that this has been the ‘go to’ emergency step that is more effective than a traditional mail recall.

At it’s core, Sabiki Email Security has been developed to target the most advanced of Email attacks, namely Phishing and other BEC (Business Email Compromise) incidents. However due to the dynamic nature of the model, it can inherently learn to target any email type.

For example, with the training data we have used to prime the engine, it has been tested to exceed standard Spam capture rates hence you will note we refer to Sabiki as an Anti-Phishing and Anti-Spam solution.

We have seen examples of customers in specific industries where they deal heavily in marketing type email communication and messages that traditional engines would mark as spam consistently and after a number of model training cycles have been able to tune the Sabiki engine to a point where their ‘spammy’ mail flow is recognized as good while regular spam is still captured correctly.

Yes, Sabiki has an additional engine built-in for attachment scanning. While it is not the core function of the solution, we ensure to give any attachment a ‘second check’ after it passes through the 365 attachment scanning workflow.

Sabiki Email Security does not sit at the Gateway.

It is an API based security solution and as such makes it simple to deploy without the need to re-direct mail or make changes to MX records. As a result of this design Sabiki is not involved in the routing or delivery of email, and therefore there are no options in relation to custom mail routing.

Another benefit of utilizing and API based security solution is that it simplifies troubleshooting of mailflow, Sabiki hooks in the instant the delivery routing is complete and is therefore exempt from any involvement in connection level/routing issues that may arise.

The Sabiki Email Security platform supports an MSP deployment out-of-the-box.

You can manage multiple email tenants and within each, multiple domains all from a single console.

There is a unique model per Tenant and each tenant can be viewed and managed in a segregated fashion.

Yes, we have granular role based access rules that can be setup to allow a customer to log into the Sabiki platform but see only their environment details. In addition to this, we can place restrictions over what the MSP is allowed to see within the customer mail environment. There are some powerful features such as email analysis that the customer might want to exclusively view and control for example while the MSP may be responsible to assisting in model tuning.

No, one of the core principles of Sabiki Email Security is that each customer has a unique mail ‘fingerprint’ or ‘mail flow profile’, so it is important to maintain a unique engine model per customer. When a 365 tenant is enrolled into the Sabiki console, a unique model is generated and maintained for that tenant and all of its subsequent training cycles.

 

Absolutely, we love working with MSPs and Channel Partners!

Please get in touch with us via sales@sabiki.ai and we can discuss crafting a unique offer that suits your business objectives.

Couldn't find an answer?

Contact our Support Team