Viewing email YARA analysis alert details grouped by alert in the Web UI

Prev Next

The eAlerts > Alerts page of the Email Security - Server appliance lists the results, grouped by alert, of a YARA rule match on the header or within an email message body. The attachments and URLs that are extracted from the email message body based on email YARA analysis are sent to the DTI Cloud for analysis if they are detected as malicious.

EX_EmailYARAAnalysis_ViewAlert_scap.png
To view the email YARA analysis alert details grouped by alert:
  1. In the Web UI, click the eAlerts tab.

  2. Click Alerts.

  3. To expand an entry, click the ID number in the ID column or the type name in the File Type column.