Viewing email YARA analysis alert details grouped by recipient in the Web UI

Prev Next

The Email Alerts: Email Analysis page of the Email Security - Server appliance lists the results, grouped by recipient, of a YARA rule match on the header or within an email message body. The attachments and URLs that are extracted from the email message body based on email YARA analysis are sent to the DTI Cloud for analysis if they are detected as malicious.

EX_EmailYARAAnalysis_ViewRecipient_scap.png
To view the email YARA analysis alert details grouped by recipient:
  1. In the Web UI, click the eAlerts tab.

  2. Click Recipient.

  3. Click the total number of header and email message body links in the Header column.

  4. To expand an entry, click the ID number in the ID column or the type name in the File Type column.