Messaging Gateway

 View Only
  • 1.  Analyse email in Quarantine

    Posted Jun 02, 2016 05:36 PM

    Hi,

    I want to download the attachement in a qurantined message before releasing it.

    In fact I want to analyse the email in virustotal.com.

    Is that possible?

    Thanks



  • 2.  RE: Analyse email in Quarantine

    Posted Jun 06, 2016 02:20 AM

    Hi,

    Yes (1) - open the quarantined mail, download the attachment and upload to virustotal.

    Yes (2) - on action of quarantine archive a copy of the message to a directory on your mailservers or using a honeypot

    Yes (3) - but only by using the unsopported way via support-user.

     

    Regards

    Thomas



  • 3.  RE: Analyse email in Quarantine

    Posted Oct 16, 2016 12:03 PM

    Hi,

    Thanks for your answer, but to be honest I haven't got you.

    Yes (1) - open the quarantined mail, download the attachment and upload to virustotal.

    There is no "download attachement" option in the quarantine section.

    Yes (2) - on action of quarantine archive a copy of the message to a directory on your mailservers or using a honeypot

    There is no such option in the quarantine section.

    Yes (3) - but only by using the unsopported way via support-user.

    Could you please explain further?

     

    It would be great to drop a screenshot.

     

    Thanks

     



  • 4.  RE: Analyse email in Quarantine
    Best Answer

    Posted Oct 20, 2016 11:21 AM

    Hi,

    ad 1 - ok, i'm only using incident folders and you can view the caught mail and you can click on the malicios attachment ... not my prefered of analyzing

    ad 2 - action in content rules you will find the option to archive the message. by selecting it a new window opens up and gives you the option to forward to any honeypot, or send it to a receive connector which just drops the mail to a queue ...

    ad 3 - ssh to your cc, set-support is documentented e.g. here https://support.symantec.com/en_US/article.TECH235117.html

    Then explore the dirs /data/bcc/work/cfi/...

    BUT BE CAREFUL - linux knowledge is a must! And dont call support after that if you broke something!

    Thomas

     



  • 5.  RE: Analyse email in Quarantine

    Posted Oct 20, 2016 12:31 PM

    Many Thanks Thomas.

    Second options looks the most hany one to me. Hope things get easier in next releases.