About impersonation detection rules

Prev Next

Impersonation detection rules enable the Email Security - Server appliance to detect and generate alerts for email sender impersonation attempts. To identify potential impersonation, you can create impersonation detection rules for individuals in your organization who are likely to be targeted, such as executives.

High Confidence Impersonation Alert

Two scenarios produce a high confidence impersonation alert:

  • When an impersonation engine matches email headers with a weight result between 80-99.

  • When the impersonation engine matches both cases: 1) email headers with a weight result between 50-79, and 2) aTrellix CEO impersonation YARA rule that matches the email body and subject.

Low Confidence Impersonation Alert

A low confidence impersonation alert is created when the impersonation engine matches email headers with a weight result between 50-79.

To generate email sender impersonation detection alerts or block email for senders that match the impersonation detection rules, you must:

  1. Enable riskware protection. See Enabling or disabling Trellix riskware detection.

  2. Enable one or more of the following impersonation riskware policy rules using the Web UI or CLI. See Enabling impersonation riskware policy rules.

    • 65027, High Confidence Email Impersonation Weights 80-99 Matched

    • 65028, Low Confidence Email Impersonation Weights 50-79 Matched

  3. Include email addresses for executives in the impersonation rules. The SMTP header email address is analyzed.

  4. Include known name derivations that may be used in email correspondence for the display name of the From/Reply-to header to the Valid Name(s) of the impersonation detection rule.

    Valid Name(s): Harold Stubbs, H Stubbs, Mr. Stubbs Valid Email(s): harold.stubbs@malware.com

Note

The impersonation engine will primarily match on the display name of the From and Reply-to headers.

See Enabling or disabling blocking emails based on riskware detection custom policy rules.

When an email sender impersonation riskware alert is generated due to sender impersonation, the email is listed on the eAlerts > Riskware tab. If riskware alerts are not enabled, alerts are not generated.

If the block option is enabled, email detected due to impersonation is blocked. The blocked email is listed in the eQuarantine tab labeled with a Riskware badge.

Riskware alerts include information on the detected impersonation in the Impersonation Rule field.