analysis custom blacklist sha256

Prev Next

Adds a rule to a custom blacklist based on the SHA-256 hash file.

A blacklist allows you to control which messages that contain an attachment must be considered malicious based on the matched known rule entries. The appliance immediately marks the attachment within an email message for quarantine if it includes the SHA-256 hash file.

You can add up to 10,000 blacklist entries to the appliance database.

Note

This command replaces the deprecated custom blacklist sha256 <sha256> command introduced in Release 7.7.

Syntax

[no] analysis custom blacklist sha256 <sha256> [signature <sha256Signature>]

Parameters

no

Use the no form of this command to delete the blacklist rule based on the SHA-256 hash file.

<sha256>

The specific SHA-256 hash file that is added as a blacklist rule.

signature

(Optional) The SHA-256 signature that is associated with the specific SHA-256 hash file.

<sha256signature>

(Optional) The specific SHA-256 signature.

Example

The following example adds the SHA-256 hash file "874b0f0ba2cf612a195be31816a28d16a4a52847cdd45ce8c4b2670a0a0c1ad1" and the associated SHA-256 signature "Custom.Blacklist" to a custom blacklist:

hostname (config) # analysis custom blacklist sha256 874b0f0ba2cf612a195be31816a28d16a4a52847cdd45ce8c4b2670a0a0c1ad1 signature Custom.Blacklist

The following example deletes the SHA-256 hash file "874b0f0ba2cf612a195be31816a28d16a4a52847cdd45ce8c4b2670a0a0c1ad1" and the associated SHA-256 signature from a custom blacklist:

hostname (config) # no analysis custom blacklist sha256 874b0f0ba2cf612a195be31816a28d16a4a52847cdd45ce8c4b2670a0a0c1ad1

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Email Security — Server: Release 7.9

  • File Protect: Release 7.7.2

  • Network Security: Release 7.9