Adds a rule to a custom blacklist based on the SHA-256 hash file.
A blacklist allows you to control which messages that contain an attachment must be considered malicious based on the matched known rule entries. The appliance immediately marks the attachment within an email message for quarantine if it includes the SHA-256 hash file.
You can add up to 10,000 blacklist entries to the appliance database.
Note
This command replaces the deprecated
custom blacklist sha256 <sha256>command introduced in Release 7.7.
Syntax
[no] analysis custom blacklist sha256 <sha256> [signature <sha256Signature>]
Parameters
no
Use the no form of this command to delete the blacklist rule based on the SHA-256 hash file.
<sha256>
The specific SHA-256 hash file that is added as a blacklist rule.
signature
(Optional) The SHA-256 signature that is associated with the specific SHA-256 hash file.
<sha256signature>
(Optional) The specific SHA-256 signature.
Example
The following example adds the SHA-256 hash file "874b0f0ba2cf612a195be31816a28d16a4a52847cdd45ce8c4b2670a0a0c1ad1" and the associated SHA-256 signature "Custom.Blacklist" to a custom blacklist:
hostname (config) # analysis custom blacklist sha256 874b0f0ba2cf612a195be31816a28d16a4a52847cdd45ce8c4b2670a0a0c1ad1 signature Custom.Blacklist
The following example deletes the SHA-256 hash file "874b0f0ba2cf612a195be31816a28d16a4a52847cdd45ce8c4b2670a0a0c1ad1" and the associated SHA-256 signature from a custom blacklist:
hostname (config) # no analysis custom blacklist sha256 874b0f0ba2cf612a195be31816a28d16a4a52847cdd45ce8c4b2670a0a0c1ad1
User role
Admin or Operator
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Email Security — Server: Release 7.9
File Protect: Release 7.7.2
Network Security: Release 7.9