How it works

We read the attack, not the address.

Filters ask where an email came from. StrongestLayer asks what it is trying to do. Here is the whole approach, in plain terms.

The problem

The attack passes every check.

Attackers now send from real accounts on Microsoft 365 and Google Workspace, and from clean domains they register themselves. Authentication passes. Reputation is spotless. There is no bad indicator left to match. The message is still an attack.

Accounts Payableaccounts@esquare-billing.com
Updated remittance details for invoice 88421
SPFPass
DKIMPass
DMARCPass
Sender reputationClean
TRACE is reading the intent…
✗ Blocked · Invoice fraud

So we read the structure underneath.

Strip away the sender, the branding, and the wording, and every attack has a spine that does not change. We call it the attack's genome, and TRACE resolves it for every message from three questions.

Axis 01 · Intent

What does it want?

A credential, a payment redirect, a data release. The goal of the message, classified across more than forty attack subtypes. This is the most stable part of any attack.

Axis 02 · Evasion

How does it get in?

The techniques used to get past filters and authentication: compromised accounts, look-alike domains, QR payloads, hijacked threads. Thirty-six techniques, tracked as defenses harden.

Axis 03 · Personalization

How does it earn the click?

What the message knows about its target: the named vendor, the live invoice, the person who signs the checks. This is what makes a generic lure read as real.

Two gates, one spine

Land, then be believed.

Every attack that succeeds clears two gates. It has to land, getting past the filters. Then it has to be acted on, convincing the person who opens it. Evasion is built for the first gate, personalization for the second. Reading both is how TRACE sees the attack whole.

The path of an attack
Sent
Machine gate
Inbox
Human gate
Acted on
Machine gate: does it land?Human gate: is it believed?
Why it holds

Attackers rotate. The genome stays.

A domain can be burned and replaced in minutes. Mailboxes, brands, and wording all change from message to message. The structure underneath does not, because it is what makes the attack work. A detection keyed to the genome keeps matching after every indicator it started with is gone.

The attacker rotates infrastructure
acme-billing-secure.com acmelogisticss.com acme-invoices.net
Same genomeVendor invoice fraud · hijacked thread · named supplier
The payoff

Thirty minutes becomes thirty seconds.

The genome is also the evidence. Every verdict arrives with what the attack wants, how it got in, and how it was meant to earn the click, on one panel, in plain English. An analyst reads it and agrees or contests it. No pivoting across logs and threat feeds to reconstruct the story.

Updated remittance details for invoice 88421accounts@esquare-billing.com · first contact
Malicious · ~30s
Intent
AiTM phishingVendor / invoice fraud
Evasion
Look-alike domainAiTM proxyMulti-hop redirect
Personalization
Named vendorPayment cycle timing

See it reason about your mail.

Live in 15 minutes · No MX changes · SOC 2