CUPELON

Features

Everything Cupelon does to protect your organization from email threats, built for environments where data can't leave your boundary.

Domain Reputation Tracking

Cupelon builds sender domain reputation from your users' native email behavior. When users flag messages as junk or rescue them, those signals feed into a rolling reputation score per sender domain.

Key Capabilities

  • Crowdsourced signals: Reputation is built from real user behavior across your organization — not external feeds
  • Deduplication: Multiple reports from the same user don't inflate scores — each user counts once
  • Auto-decay: Reputation resets over time so domains can recover from false positives
  • Org-specific intelligence: Spear phishing targeting your users gets caught, even if no external feed has seen it

Contextual Warning Banners

Color-coded warning banners are injected directly into email bodies based on threat level. Banners apply retroactively — when a domain's reputation changes, all existing messages from that domain are updated.

YellowCaution

Early warning — multiple users have flagged this sender

OrangeWarning

Pattern match — message resembles known phishing campaigns

RedAlert

High threat — strong consensus or confirmed threat indicators

BlueNotice

Mixed signals — likely newsletter or nuisance mail, not malicious

Customization

  • Custom templates: Full HTML editor per banner state — match your organization's branding
  • Configurable thresholds: Adjust sensitivity levels via the dashboard
  • Safe domain allowlist: Bypass banner logic entirely for trusted senders

Inline Phishing Training

Instead of sending fake phishing emails, Cupelon injects educational training panels into real phishing attempts. Users learn from actual threats at the point of attack — not from simulations they learn to ignore.

Each email is analyzed across multiple dimensions — link integrity, sender authentication, language patterns, domain reputation, and more. The composite analysis determines whether a training panel is shown and at what severity level.

What Gets Analyzed

Domain reputation & age
Threat indicator matches
Campaign pattern similarity
Urgency & pressure language
Link display mismatches
Email authentication failures
Reply-to address anomalies
Attachment risk assessment
Lookalike domain similarity
Character pattern anomalies

Why Not Simulations?

Traditional Simulation

  • Expensive per-user licensing
  • Users learn to spot fake emails, not real ones
  • Creates resentment and distrust
  • Separate portal from daily workflow
  • Periodic campaigns miss day-to-day threats

Cupelon Inline Training

  • Included in Pro and Enterprise tiers
  • Users learn from the actual attacks they receive
  • Educational, not punitive
  • Delivered in the inbox — zero friction
  • Continuous, real-time feedback loop

Lookalike Domain Detection

Algorithmic detection of impersonation domains using multiple analysis techniques. No static blocklists to maintain — catches zero-day lookalike domains the moment they appear in your mail flow.

Detection Capabilities

  • Visual impersonation: Detects characters that look similar across different scripts and alphabets
  • Typo variants: Catches common misspellings and character transpositions of your protected domains
  • Structural tricks: Identifies subdomain abuse, hyphenation attacks, and TLD swaps

How It Differs

  • No blocklist maintenance: Purely algorithmic — no feeds to subscribe to or lists to update
  • Zero-day coverage: Catches brand new domains on first appearance
  • Configurable sensitivity: Adjust the detection threshold to balance coverage vs. false positives

Threat Correlation

Cupelon automatically extracts indicators of compromise from flagged emails and correlates them across sender domains. When the same threat indicators appear from multiple senders, the system recognizes coordinated campaigns and elevates the threat level.

IOC Extraction

URLs, contact information, and content fingerprints are automatically extracted from flagged messages and tracked across your organization.

Campaign Detection

Messages with similar content are automatically clustered together, revealing phishing campaigns that use slightly modified templates across different sender domains.

Cupelon Threat Network

The Cupelon Threat Network is a crowd-sourced intelligence layer built from anonymized threat data contributed by organizations across the community. Every participant makes the network stronger — and gets stronger protection in return.

Available to all Community tier users at no cost. The more organizations that participate, the faster new threats are identified and the more accurate reputation scores become.

Cross-Organization Intelligence

  • Domain reputation: Aggregate sender reputation across all participating organizations — not just your own
  • Campaign clusters: Detect coordinated phishing campaigns that span multiple targets
  • URL reputation: Community-wide tracking of malicious URLs and redirect chains

Cupelon Score Threat Scoring

  • Composite score: A single 0–100 threat score per domain, combining reputation signals from across the network
  • Real-time updates: Scores adjust as new reports flow in from community members
  • API access: Query Cupelon Scores programmatically to integrate with your existing security tooling

Alerting & Notifications

Configurable alert rules fire on threat events and deliver notifications to your preferred channels with cooldown timers to prevent alert fatigue.

Microsoft Teams

Rich card notifications with threat details

Email (SMTP)

HTML alerts to your security team distribution list

Google Chat

Webhook notifications for Google Workspace environments

Product Dashboard

Full-featured management dashboard with no external dependencies — works in air-gapped environments with no internet access required.

  • Domain reputation overview
  • Threat indicator tracking
  • Event timeline & search
  • Alert rule management
  • System configuration
  • Banner template editor
  • Safe domain allowlist
  • Audit log viewer
  • License & system status

See It in Action

Deploy in 2 minutes, see results immediately. No sales calls required.