Threat Response Auto-Pull is an email security platform that automatically removes malicious emails from user inboxes after delivery. When malicious email is detected, the system receives alerts with message information and connects to Exchange, Office 365, or Gmail to move messages to quarantine. The platform includes built-in logic that tracks forwarded messages and distribution list recipients to locate and retract emails across multiple users. It features adapters for connecting various sources including Exchange, Office 365, Gmail, CSV files, FireEye EX, and JSON sources. Users can upload search results or CSV files to initiate quarantine actions for single or multiple emails. The system automatically analyzes messages sent to abuse mailboxes against intelligence and reputation systems to identify malicious content. The platform can respond to confirmed user interactions with malicious content by resetting passwords or locking user accounts in Microsoft Active Directory or Okta when configured. The solution can be deployed in the cloud or on-premises through VMware and AWS, providing compatibility with various email systems including Microsoft 365, Exchange, and Google Workspace.