To determine whether a password-protected attachment is malicious, the appliance must determine the password so that it can open the attachment and scan it for malware.
The appliance uses the following steps to detect and extract passwords from attachments:
Analyzes the attachments of an email to determine if they are password-protected
Looks for the password in the attachment itself
Looks for the password in the email header information, such as from, to, and subject, or the email body
Looks for the password in images attached to the email using OCR
For details on configuring password extraction, see: