In some embodiments, a severity or priority for a message may be assigned, either manually or on the basis of rules, as described above. The severity or priority value can be associated with the threat information and can be input into the integrations. Data derived from collected message threat information can be further provided to a malware analysis device 1830 within the network to address threats at the perimeter, or malware analysis devices in other networks. In some embodiments, the threat information can be automatically provided to the network security device if the threat information is associated with a severity or priority level over a predetermined threshold. The user may specify not to automatically provide some threat information to a third-party integration. As a non-limiting example, the user may choose not to automatically send attachments that are PDFs, or otherwise contain personal identifying information (PII). Once the user has determined that there is no PII, the user may manually send the threat information to the malware analysis device.