The Supply Chain Impersonation Detection feature prevents attempts to impersonate a business partner, client, or company employee. This feature is automatically enabled.
Email feature extraction and Trellix Advanced URL Detection Engine (FAUDE) are used with the supply chain impersonation feature to scan, analyze, and generate a riskware alert.
The Supply Chain Impersonation Detection feature allows organizations to protect from fraudulent activity between an organization and its vendors. This feature applies behavioral analysis patterns alongside intelligence from our cloud detection engines, strengthening our impersonation protection specific to supply chain vendors. This feature is automatically enabled on the appliance.
Email feature extraction and Trellix Advanced URL Detection Engine (FAUDE) are used with the supply chain impersonation feature to scan, analyze, and generate a riskware alert.
The Email Security - Server appliance uses email feature extraction to automatically allow the appliance to scan email and extract sender domain data. Email feature extraction is automatically enabled.
When certain conditions are met, the appliance generates a riskware alert for supply chain impersonation.
Prerequisites
An established connection between the Email Security - Server appliance and the Internet.
You are logged in to the Web UI with Admin and Operator access.
To enable the riskware rule for supply chain impersonation using the Web UI:
Go to the Settings > Riskware Policy page.
In the Riskware Policy Rules table, select rule id 65038.
Select Alert Only and clear Quarantine.
Note
Trellix recommends that you unblock emails for custom policy rule 65038 so that the Email Security appliance continues to learn and gather statistics about these suspicious domain sender emails.
To view Supply Chain Impersonator risk alerts using the Web UI:
Go to Dashboard > What's Happening.
Click on Riskware Alerts to display the Riskware Alerts page.
Click on the riskware object for custom policy rule 65038.

Click on the custom policy rule 65038 to display alert details.
