cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1083
Views
0
Helpful
3
Replies

Outbreak Filters

When in the body of the message has a link to an url and it downloads a .pdf or .doc file or whatever the extension and this is a malicious file, CISCO MAIL SECURITY analyzes this file ???

3 Replies 3

C100V

No. The ESA does not download the file and analyze it.

The ESA may know that the URL has a bad reputation and will act on that, but it doesn't follow it and download the payload.


Robert Sherwin
Cisco Employee
Cisco Employee

One article that may be helpful to you for this:

Testing Outbreak Filter URL Rewriting

 

If there is a URL that is suspicious, be sure to have URL Filtering turned on, and the URLs themselves written into mail logs:

ESA URL Filtering Enablement and Best Practices

 

With AsyncOS 11.1 - Email Security will now scrutinize URL shortened links as well.

 

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: