Managing riskware policies

Prev Next

Riskware policies allow you to identify files that are similar to malware, but that are not intended to be malicious. A file that is not a malicious threat might display behavior that affects threat detection, such as installing unwanted programs, modifying system settings, or reducing the overall performance of the appliance. Types of riskware include Potentially Unwanted Programs (PUPs), Potentially Unwanted Applications (PUAs), adware, and hacker tools.

To associate a riskware policy with a domain:

  1. On the Domains page, select a domain.

  2. Click the Manage link next to Riskware Rule Policy.

    The subsequent screen displays the riskware rule policy, if any, associated with this domain or inherited from the domain group.

  3. Click Change.

  4. Select a policy, or None.

  5. Click OK.

  6. Click Save.

To create a new riskware policy, see Creating and deleting policies.

ETP_riskwarerules.png

To manage a riskware policy:

  1. Select a riskware policy.

  2. Next to Rules, click Manage.

  3. For each riskware rule you can select Disabled, Monitor, Alert, or Alert and Quarantine.

    Monitor

    Analyzes the email for riskware. Trellix Email Security — Cloud does not generate an alert or quarantine the email if the rule matches.

    Alert

    Analyzes the email and generates an alert if the rule matches.

    Alert and quarantine

    Analyzes the email, generates an alert, and moves the email to quarantine if the rule matches.

    Disabled

    Does not analyze emails for riskware.

  4. Click Save.

The following table describes some of the riskware rules that can trigger a riskware alert. You can see the full list of riskware policy rules in the Web UI.

Riskware policy rule

Trigger condition

65000 Jar Files Delivered Via Email Attachment Or Link

Jar files are delivered through email attachments or links.

65001 Encrypted MS Office Document

Microsoft Office files in emails are encrypted.

65002 PDF, HWP or MS Office Files With Network Activity Policy

Microsoft Office files are used for network activity.

65003 Executable Delivered via Email Attachment or URL Link within Email Body

Email attachments have suspicious executable files (such as PEEXE or PEDLL).

65004 Script Delivered via Email

Email messages include scripts.

65007 MS Office Document With Embedded Object

Microsoft Office files have embedded objects.

65008 MS Office Document With Macro Activity

Microsoft Office files have macro activity.

65009 Non Executable file Connecting to Non-Standard High Port

Non-executable files that connect to ports above 1024.

65010 MS Office Document with Network Activity and Embedded Object or Macro

Microsoft Office files have network activity and embedded objects or macros.

65011 Uncommon File Types Delivered Via Email BAT, CPL, LNK, COM, CMD, MHT, PIF, PUB, HLP, HTA, ISO

Emails have file attachments with any of the following file types: BAT, CPL, LNK, COM, CMD, MHT, PIF, PUB, HLP, HTA, ISO

65012 MS Office Document With Macro Activity Dropping a exe file

Microsoft Office files have macro activity that write executable files.

65013 Password From Web Forms Found in Plaintext Http_Request

Email Web forms have passwords that are sent as plaintext HTTP requests.

65016 Email with shortened link

Emails contain URLs that have been shortened.

65017 Email with MS Access DB Attached

Email messages have Microsoft Access database attachments.

65020 MS Office Document running Flash Events

MS Office files are running flash events.

65021 MS Office Document With Password Protected Macro

MS Office files have password protected macros.

65022 Login Page Sent as Email Attachment

Email messages send an attachment with a link to a login page.

65023 Password Protected Zip .rar Archives

Email messages send attached password protected zip .rar archives

65024 Uncommon Filetype Observed. Setting Content-ms Extension

Uncommon Filetype Observed. Setting Content-ms Extension

65025 Suspicious File With Disagreeing Extension and MagicBytes

Email messages send suspicious file with disagreeing extension and magicbytes

65027 High Confidence Email Impersonation

Email impersonation detection has determined that email impersonation is very likely.

For more details see Impersonation Detection in Email Security - Server User Guide.

65028 Low Confidence Email Impersonation

Email impersonation detection has determined that email impersonation is somewhat likely.

For more details see Impersonation Detection in Email Security - Server User Guide.

65029 Provided list of extensions marked for Policy Blocking

Provided list of extensions marked for policy blocking

65030 Encrypted PDF Document

Email messages send an attachment with encrypted PDF document

65031 Potential Risky ScreenSaver Indicator

Potential risky screensaver indicator

65033 HTML Redirector Sent as Email Attachment

Email messages send an attachment with HTML code for redirection

65034 Low Confidence Malware Guard on EX

Malware Guard scores a binary file as riskware rather than malware

65035 Policy Low Confidence Malware Guard on NX/AX

Malware Guard scores a binary file as riskware rather than malware

65036 Matching Recipient and Message ID Domains

An email message header has matching domains for recipient and message ID.

65037 Suspicious DAA Archive Delivered via Email

Email messages have suspicious Direct Access Archive file attachments.

65041 Attacker Abused Legit Tool

Detection of productivity or other legitimate tools that are known to be leveraged as threat actor tactics, techniques, and procedures (TTPs).

65043 FireWall/AV Discovery via WMI

FireWall/AV discovery via WMI

65044 Corrupt Windows PE File

Email messages send an attachment with corrupt Windows PE file

65045 Office Document with Template Link

Email messages send an attachment with Office document with template link

65046 MS Excel Formula Macro Sheet

Email messages send an attachment with MS Excel formula macro sheet

65047 MS Office Document with Embedded SWF

Email messages send an attachment with MS Office document with embedded SWF

65048 Policy MSIL Reflective Loader File thru Emails

Email messages send an attachment with MSIL reflective loader file

65049 Policy File NSIS Delivered thru Emails

Email messages send an attachment with file NSIS

65050 Policy File ONENOTE with Embedded Object Delivered thru Emails

Email messages send an attachment with file ONENOTE with embedded object

65052 Potential ZipBomb

Potential zipbomb

65053 Policy CryptoJS Used in JavaScript

CryptoJS used in JavaScript

65054 Policy MS Excel Formula Python Script

MS Excel formula python script

65055 Policy QR Code Observed

QR code observed

65056 Policy JScript Deobfuscation Functions Observed

JScript deobfuscation functions observed

65057 Policy Branchlock Obfuscated JAR File

Branchlock obfuscated JAR file

65059 Policy Mitre Multiple Tactics Observed

Mitre multiple tactics observed

65060 Policy RDP Files Delivered Via Email Attachment Or URL

RDP files delivered via email attachment or URL

65061 Policy MSI File with Custom Action Scripts

Policy MSI File with Custom Action Scripts

65062 Policy SVG File Delivered via Email

Policy SVG File Delivered via Email

65063 Policy Password Protected HWP Document

Policy Password Protected HWP Document

65064 Policy Packer Obfuscated MSIL

Policy Packer Obfuscated MSIL

65065 Policy ClickOnce Deployment Manifest

Policy ClickOnce Deployment Manifest

65066 Policy Password Extraction Failed

Policy Password Extraction Failed

65067 Policy ClickOnce Deployment Manifest Process

Policy ClickOnce Deployment Manifest Process

65068 Policy Double Extension FileName

Policy Double Extension FileName

65069 Policy PDF Embedded Script

Policy PDF Embedded Script

65070 Policy Theme File Delivered via Email

Policy Theme File Delivered via Email

65071 Policy URLFeature CloudFlare Recaptcha Reasons

Policy URLFeature CloudFlare Recaptcha Reasons

65072 Policy Document Files with Embedded URL

Policy Document Files with Embedded URL