Retroactive detection

Prev Next

Retroactive detection allows you to identify malicious objects that were previously missed. With retroactive detection, the Email Security - Server appliance compares past submissions with updated security content. If new malicious objects or riskware is detected, the Email Security - Server appliance generates an alert and can take remediation actions on the missed email. You can configure remediation actions on retroactive email using the Web UI and CLI.

This feature uses SHA-256 hashes for attachments and URLs to detect objects.

The Email Security - Server appliance receives a list of SHA-256 hashes from the DTI network through security content updates. The hashes are compared against a list of submissions from the database that were previously determined to be nonmalicious. By default, the retroactive hunt time period is unlimited, but you can configure it using the analysis retro-hunt time command. If the hash is detected as malicious, the Email Security - Server appliance generates a retroactive alert. The submission status for a retroactive alert of a hash is marked as dti_detection in the output of the show submission id command.

When the Email Security - Server appliance detects an SHA-256 match after a security content update from the DTI Cloud, a previously undetected malicious blacklist attachment will be retroactively marked as malicious and the appliance will send an alert or take remediation actions on the email.

When Advanced URL Defense is enabled on the appliance, the Email Security - Server appliance can alert on previously undetected URLs. The Email Security - Server appliance sends the suspicious URLs to the Trellix Advanced URL Detection Engine (FAUDE) for analysis. When the Email Security - Server appliance is deployed in block mode and enabled to rewrite URLs within an email message, URLs are rewritten and the email will be delivered to the recipient. If a verdict is returned later from FAUDE that the URL is malicious, the Email Security - Server appliance generates a retroactive alert. For details about Advanced URL Defense and rewriting URLs, see About advanced URL defense.

When riskware detection is enabled on the Email Security - Server appliance, retroactive riskware detection is enabled by default. Types of riskware include Potentially Unwanted Programs (PUPs), Potentially Unwanted Applications (PUAs) adware, and hacker tools. You must enable at least one matched policy rule on the Email Security - Server appliance. If an earlier submission is now identified as riskware, you can choose to have the Email Security - Server appliance generate a riskware alert on a submission, block an email from being delivered to the intended recipient or take remediation actions on the email. For details about Riskware, see Riskware. For details about how to enable or disable riskware detection custom policy rules, see Enabling or disabling riskware detection custom policy rules. For details about how to enable or disable blocking emails based on riskware detection, see Enabling or disabling blocking emails based on riskware detection.

When the Email Security - Server appliance is enabled to remediate retroactive email that contains malicious objects or riskware, email can be automatically or manually deleted or quarantined from a user's email inbox.

Note

Retroactive alerts for objects require a one-way, one-way with override, or two-way CONTENT_UPDATES license. Retroactive alerts for URLs identified by the Trellix Advanced URL Defense (FAUDE) service require a one-way with override or two-way CONTENT_UPDATES license. See the Email Security — Server System Administration Guide for information about overriding a one-way CONTENT_UPDATES license.

Task list for managing retroactive detection

Complete the steps for managing retroactive detection in the following order:

  1. Log in to the CLI.

  2. Validate DTI access on the Email Security - Server appliance by using the show fenet status command. For details about how to validate DTI access, refer to the Email Security — Server System Administration Guide.

  3. Enable Advanced URL Defense. For details about Advanced URL Defense, see Enabling or disabling advanced URL defense.

  4. When the Email Security - Server appliance is deployed in block mode, enable rewriting URLs within a message. For details about how to enable rewriting URLs, see Enabling or disabling rewriting URLs.

  5. Track the total number of malware object alerts that are related to retroactive detection by using the What's Happening panel of the Email Security - Server Dashboard.

  6. Configure remediation actions for retroactively detected email. For details, see Retroactive remediation.