09-06-2017 05:35 AM - edited 03-08-2019 07:23 PM
I am looking to create a content filter that detecteds header for postive APM messages and send them to a quaratine. Would you be able to provide what the header looks like with a postive APM verdict?
Thanks!
Solved! Go to Solution.
09-06-2017 07:53 AM
Hello,
It sounds like maybe the X-Amp-Result: MALICIOUS header is what you're looking for. Here are some examples :
X-Amp-Result: CLEAN X-Amp-Result: MALICIOUS X-Amp-Result: UNKNOWN
X-Amp-Result: UNSCANNABLE
Hope that helps!
Thanks!
-Dennis M.
09-06-2017 07:26 AM
In the amp config, you can set a custom header, and then do whatever you need to based on it. You probably want to "deliver as is", maybe drop the malware
09-06-2017 07:29 AM
Thanks for the info. Isn't there already a default header that is included? Thats what I am looking for.
09-06-2017 07:32 AM
09-06-2017 07:53 AM
Hello,
It sounds like maybe the X-Amp-Result: MALICIOUS header is what you're looking for. Here are some examples :
X-Amp-Result: CLEAN X-Amp-Result: MALICIOUS X-Amp-Result: UNKNOWN
X-Amp-Result: UNSCANNABLE
Hope that helps!
Thanks!
-Dennis M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide