The embedded URL analysis feature allows the Email Security - Server appliance to extract suspicious URLs that are embedded in a PDF file or a Microsoft Office file within an email message body. When the Email Security - Server appliance extracts a suspicious URL from the PDF file or the Microsoft Office file in an email message, it sends the URL to the URL analysis service for analysis. When guest images updates are downloaded and installed on the Email Security - Server appliance, they are used to extract the suspicious URLs from a Microsoft Office file in an email message during dynamic analysis. Before the Email Security - Server appliance submits the PDF file or the Microsoft Office file for analysis, a verdict is determined for the embedded URL based on custom allowed and blocked lists, Advanced URL Defense, typo squatting, and so forth.
Note
Before the Email Security - Server appliance submits a Microsoft Office file for analysis, a verdict cannot be determined for the embedded URL based on URL Dynamic Analysis (DUA).
If the embedded URL that is extracted from the PDF file or the Microsoft Office file are detected as malicious, the Email Security - Server appliance immediately blocks the email from being delivered to you and marks the malicious email for quarantine.
Note
The embedded URL analysis feature is enabled by default.
Usage guidelines
Trellix recommends that you follow these usage guidelines when you are managing embedded URL analysis:
Detection can be improved when you enable Advanced URL Defense to detect matched URLs that are embedded in PDF or Microsoft Office files. For details about Advanced URL Defense, see Enabling or disabling advanced URL Defense on .
Note
URLs that are embedded in PDF and Microsoft Office files will not be rewritten even when the Email Security - Server appliance is deployed in block mode and Advanced URL Defense is enabled.
Detection can be improved when you enable URL Dynamic Analysis to detect matched URLs that are embedded in a PDF file. These URLs point to malicious objects such as ZIP, EXE, PDF, DOC, and DOCX file types. For details about URL Dynamic Analysis, see Enabling or disabling URL Dynamic Analysis on .
Note
URL Dynamic Analysis cannot detect matched URLs that are embedded in a Microsoft Office file.
You can verify that the appliance is enabled to extract suspicious URLs that are embedded in PDF and Microsoft Office files. Use the
show static-analysis configcommand.You can configure the maximum number of embedded URLs extracted from PDF and Microsoft Office files. For details about how to configure the maximum number of embedded URLs, see Configuring the number of embedded URLs to extract from files on .
You can track the number of malicious attachments that are related to embedded URLs in PDF and Microsoft Office files by using the What's Happening panel of the Dashboard.