Skip to main content

What this integration contributes

Cofense Triage can contribute normalized employee-reported email and investigation outcomes. Reviewed examples include:
  • phishing.real.reported — reports real phishing emails
  • email.suspicious.reported — reports suspicious emails
  • phishing.real.targeted — targeted by real phishing campaigns
See how integration data becomes signals.

What you need

Cofense Triage uses OAuth2 client credentials. Create an API application in your Triage tenant and copy its client ID and client secret. There is no browser consent step — you paste both values into Living Security and it requests the token itself.

Setup

1

Create a dedicated Cofense credential

In Cofense Triage, create an API application that can read reports. Keep the credential limited to reporting access. Record the client ID and client secret — Triage shows the secret once.
2

Confirm the Triage hostname

Record your full tenant hostname, such as acme.managedphishme.com or the hostname assigned to your Cofense environment. Omit https:// when entering it in Living Security.

Verify and troubleshoot

Verify that the connection test can read the current user and reports before waiting for the first synchronization.
Replace the client secret — it may have been rotated or revoked. Confirm that the hostname belongs to the same tenant that issued the credential.
The credential cannot read reports. Grant the minimum reporting permission required by your Cofense tenant, then reconnect.
If your Triage tenant restricts API access by source IP address, this integration needs two sets of addresses allowlisted. Living Security mints the access token itself and renews it continuously, so token requests and scheduled syncs leave from different networks — and on Triage they reach the same hostname.
Reporter enrichment is available only on connection variants that expose the reporter endpoint. Report-derived signals can still populate from supported report data.