The Advanced URL Defense feature allows you to identify suspicious URLs that are embedded in an email message. This feature prevents access to these URLs so that your system will not be infected by malware.
When the Email Security - Server appliance identifies a suspicious URL within an email message body, it redirects the URL to the Dynamic Threat Intelligence (DTI) Cloud for a complete analysis. In conjunction with redirecting the suspicious URL to the DTI Cloud, if URL rewriting is enabled, the Email Security - Server appliance rewrites all URLs in the email, whether or not they are in the process of being analyzed by the Trellix Advanced URL Detection Engine (FAUDE). If the URL is detected as malicious, you are redirected to a page indicating that the URL is blocked and that the site contains malicious content. If the URL is detected as suspicious, you are redirected to a page informing you that the site might contain malicious content.
Note
URLs that are defined in a custom whitelist are not rewritten. See Custom whitelists, blacklists, and passwords.
You can customize the block and warning pages by using Trellix-hosted pages or your own hosted pages for Advanced URL Defense. For details about how to customize the block and warning pages, see Customizing block and warning pages for advanced URL defense.
Task list for managing advanced URL defense
Complete the steps for managing Advanced URL Defense in the following order:
Log in to the CLI to specify the settings for Advanced URL Defense.
Verify that the Faude service address is set to
unity.fireeye.comusing theshow fenet dti configurationcommand. Use theshow fenet dti configurationcommand. For details about how to set the DTI server address for Faude, refer to the Email Security — Server System Administration Guide.Important
By default, this address for managed appliances is the address of the managing Central Management System appliance. For more effective detection and remediation, Trellix recommends a direct connection to
unity.fireeye.com.Enable Advanced URL Defense. For details about how to enable Advanced URL Defense, see Enabling or disabling advanced URL defense.
When the Email Security - Server appliance is deployed in block mode, you have the option to enable rewriting URLs within a message. For details about how to enable rewriting URLs, see Enabling or disabling rewriting URLs.
View the statistics for the total number of URLs that have been sent to the DTI Cloud for analysis. For details about how to view the statistics for the URLs, see Viewing the statistics for the URLs.
Track the infected URLs that are related to Advanced URL Defense by using the What's Happening panel of the Email Security - Server Dashboard.