Password extraction

Prev Next

To determine whether a password-protected attachment is malicious, the appliance must determine the password so that it can open the attachment and scan it for malware.

The appliance uses the following steps to detect and extract passwords from attachments:

  1. Analyzes the attachments of an email to determine if they are password-protected

  2. Looks for the password in the attachment itself

  3. Looks for the password in the email header information, such as from, to, and subject, or the email body

  4. Looks for the password in images attached to the email using OCR

For details on configuring password extraction, see: