PhishTriage 作者: Culfig OÜ
One-click phishing triage for Gmail, Outlook Web and any page. Reads nothing until you click Analyze.
扩展元数据
屏幕截图
关于此扩展
PhishTriage tells you whether the thing in front of you is a phishing
attempt. Open the suspicious email, or the login page that feels
wrong, and click Analyze. You get a verdict with a risk score, the indicators behind it, and what to do next.
On an ordinary web page the extension holds no standing access. It reads
the page under
One exception, and your browser shows it at install: on Gmail and
Outlook Web (
from the start, because that is how the Analyze button reaches the mail
toolbar. Nothing else is touched unless you switch on an optional
feature below.
From an email it sends the subject; the sender, recipient and reply-to
addresses; the body, with quoted threads and signatures stripped; the
links; and attachment filenames, not attachment contents. Who a message
claims to be from is the strongest single signal there is. From any
other page: the title, the visible text, the links, and the full address
including path and query.
A verdict argues; an artifact proves. When a web page you analyze comes
back Malicious or Suspicious, a screenshot of the visible tab and that
page's HTML go up with it, so the site can be reported to its host or
registrar. This is the one setting here that starts on: setup shows
it, and the switch is in the popup. Nothing is captured on a benign
verdict, and nothing on Gmail or Outlook Web, where the screenshot would
be of your inbox. Webmail on any other host counts as an ordinary page,
and there the picture is of your inbox — the privacy policy names the
providers this affects. Both are held in memory for the seconds the scan
takes, never written to your disk. Confirmed malicious is kept 12 months,
suspicious 30 days, and a capture a reviewer clears is deleted at once.
Background protection checks each site as it loads and shows a
full-page warning if it is known bad. Your browser asks permission
first; decline, or revoke later. Only the hostname is sent, not the page
you are on. Separate switches send full URLs instead, and cache a site
for an hour; both off.
File protection (Chrome, Edge, Brave) checks your downloads. A
fingerprint goes up with the file's name, its size, and what the
on-device check made of it; the file itself only when you ask for that
one file, or on every download if you switch on
Deep scan every file. Another switch holds files a page builds in your
browser and asks before they save, instead of warning after. For an
ordinary download the extension fetches the file's address a second time
— a browser hands an extension a download's details, not its contents —
and that request carries your cookies as the first did.
No third-party analytics, advertising or telemetry. No identity
permission: it never asks your browser or your mail provider who you
are. Your install is identified by a random id,
replaced at registration by one our server issues; it registers once at
install, sending that id, your browser name, and an enrolment token if
an administrator set one. The feedback buttons under a verdict record
your correction on your own device and send nothing.
Sign in from the popup and the portal opens to finish the link. An
administrator links the device to your organisation there; the extension
never takes a credential. For a fleet, push an enrolment token by
managed policy and devices join at install. Policy also pins the backend
and sets the monitoring, file-protection, deep-scan and evidence
switches for everyone, in either direction, so on a managed device a
switch may already be on, or held off.
attempt. Open the suspicious email, or the login page that feels
wrong, and click Analyze. You get a verdict with a risk score, the indicators behind it, and what to do next.
On an ordinary web page the extension holds no standing access. It reads
the page under
activeTab, which exists only in the moment you click.One exception, and your browser shows it at install: on Gmail and
Outlook Web (
mail.google.com, outlook.office.com,outlook.office365.com, outlook.live.com) a content script is presentfrom the start, because that is how the Analyze button reaches the mail
toolbar. Nothing else is touched unless you switch on an optional
feature below.
From an email it sends the subject; the sender, recipient and reply-to
addresses; the body, with quoted threads and signatures stripped; the
links; and attachment filenames, not attachment contents. Who a message
claims to be from is the strongest single signal there is. From any
other page: the title, the visible text, the links, and the full address
including path and query.
A verdict argues; an artifact proves. When a web page you analyze comes
back Malicious or Suspicious, a screenshot of the visible tab and that
page's HTML go up with it, so the site can be reported to its host or
registrar. This is the one setting here that starts on: setup shows
it, and the switch is in the popup. Nothing is captured on a benign
verdict, and nothing on Gmail or Outlook Web, where the screenshot would
be of your inbox. Webmail on any other host counts as an ordinary page,
and there the picture is of your inbox — the privacy policy names the
providers this affects. Both are held in memory for the seconds the scan
takes, never written to your disk. Confirmed malicious is kept 12 months,
suspicious 30 days, and a capture a reviewer clears is deleted at once.
Background protection checks each site as it loads and shows a
full-page warning if it is known bad. Your browser asks permission
first; decline, or revoke later. Only the hostname is sent, not the page
you are on. Separate switches send full URLs instead, and cache a site
for an hour; both off.
File protection (Chrome, Edge, Brave) checks your downloads. A
fingerprint goes up with the file's name, its size, and what the
on-device check made of it; the file itself only when you ask for that
one file, or on every download if you switch on
Deep scan every file. Another switch holds files a page builds in your
browser and asks before they save, instead of warning after. For an
ordinary download the extension fetches the file's address a second time
— a browser hands an extension a download's details, not its contents —
and that request carries your cookies as the first did.
No third-party analytics, advertising or telemetry. No identity
permission: it never asks your browser or your mail provider who you
are. Your install is identified by a random id,
replaced at registration by one our server issues; it registers once at
install, sending that id, your browser name, and an enrolment token if
an administrator set one. The feedback buttons under a verdict record
your correction on your own device and send nothing.
Sign in from the popup and the portal opens to finish the link. An
administrator links the device to your organisation there; the extension
never takes a credential. For a fleet, push an enrolment token by
managed policy and devices join at install. Policy also pins the backend
and sets the monitoring, file-protection, deep-scan and evidence
switches for everyone, in either direction, so on a managed device a
switch may already be on, or held off.
评分 0(1 位用户)
权限与数据
必要权限:
- 访问您在 mail.google.com 的数据
- 访问您在 outlook.office.com 的数据
- 访问您在 outlook.office365.com 的数据
- 访问您在 outlook.live.com 的数据
可选权限:
- 下载文件和读取与修改浏览器的下载历史
- 获知浏览器导航时的行为状态
根据开发者所述,必要的数据收集:
- 个人通信
- 个人身份信息
- 网站内容
根据开发者所述,可选的数据收集有:
- 浏览活动
- 网站活动
更多信息