would like ability to mark an endpoint for further scan or analysis by SOC and get a report back , for example if a user clicks on a phishing link, or opens attachment. Just a way to proactively scan for any or to detect for anything malicious on a one time per needed bases ,