ATI badges in the Web UI

Prev Next

This topic covers the following information:

Badge colors that indicate risk levels

When Advanced Threat Intelligence is enabled, the Email Security - Server appliance Web UI visually flags an ATI alert—an MVX-verified event for which the appliance has obtained threat intelligence—by displaying a color-coded badge in the eAlerts tab and the eQuarantine tab of the appliance. The color of the badge indicates the level of risk posed to your network. In the eAlerts > Recipient page, eAlerts > Sender page, eAlerts > Alerts page, or eQuarantine page, if an alert grouping includes an ATI alert, the table row displays a Threat Info badge in the Badges column. You can click an ATI badge to drill down to the threat intelligence and other details about the alert

The color of a Threat Info badge indicates the level of risk that the attack poses to your network:

Badge

Description

icon_badge_ati_3.png

A red Threat Info badge indicates an ATI alert for a threat that poses a high risk.

icon_badge_ati_2.png

An orange Threat Info badge indicates an ATI alert for a threat that poses a medium risk.

icon_badge_ati_1.png

An amber Threat Info badge indicates an ATI alert for a threat that poses a low risk.

Note

For managed Email Security - Server appliances, ATI badges and ATI information are visible from the Central Management System Web UI only.

ATI alert badges in the eAlerts > Recipient page

The eAlerts > Recipient page lists malware alerts and associated callback activity, grouped by associated senders, attachments and embedded URLs, time frame, and malware type. A Threat Info badge appears in a table entry if threat intelligence is known for an alert in the grouping.

The following example shows the display of an eAlerts > Recipient page. The default display lists entries in reverse chronological order, shows 20 results per page, covers the previous 24 hours of network threat prevention processing, and is not filtered on any data column.

EX_ATI_alerts-recipients.png

ATI alert badges in the eAlerts > Sender page

The eAlerts > Sender page lists malware alerts and associated callback activity, grouped by associated recipients, attachments and embedded URLs, time frame, and malware type. A Threat Info badge appears in a table entry if threat intelligence is known for an alert in the grouping.

The following example shows the display of an eAlerts > Sender page. The default display lists entries in reverse chronological order, shows 20 results per page, covers the previous 24 hours of network threat prevention processing, and is not filtered on any data column.

EX_ATI_alerts-senders.png

ATI alert badges in the eAlerts > Alerts page

The eAlerts > Alerts page lists malware alerts and associated callback activity, grouped by attack (associated recipients, associated senders, attachments and embedded URLs, time frame, and malware type). A Threat Info badge appears in a table entry if threat intelligence is known for an alert in the grouping.

The following example shows the display of an eAlerts > Alerts page. The default display lists entries in reverse chronological order, shows 20 results per page, covers the previous 24 hours of network threat prevention processing, and is not filtered on any data column.

EX_ATI_alerts-alerts.png

ATI alert badges in the eQuarantine page

The eQuarantine page lists malware alerts and associated callback activity grouped by associated recipients, associated senders, attachments and embedded URLs, and email message text. A Threat Info badge appears in a table entry if threat intelligence is known for an alert in the grouping.

The following example shows the display of an eQuarantine page. The default display lists the entries in reverse chronological order, shows 20 results per page, covers the previous 24 hours of network threat prevention processing, and is not filtered on any data column.

EX_ATI_eQuarantine.png