The main features of TSME are described in this section.
Trellix® Threat Intelligence Exchange (TIE) integration for file reputation check — Supports TIE file reputation check for email attachments. It quickly analyzes files and makes informed decisions by validating the file reputation based on the information received from several sources connected to the TIE server in your environment. When the email contains a compressed file, the files are extracted and the supported types of files are sent for TIE reputation. For the list of supported compressed files, see KB89577.
Trellix Intelligent SandboxTIE reputation check for files — TSME now supports Intelligent Sandbox, an on-premise appliance that facilitates detection and prevention of malware through TIE. With Intelligent Sandbox protection, you can protect your systems from known, near-zero day, and zero-day malware without compromising on the quality of service to your network users.
Protection from Email spoofing — Protects your systems from spoofing emails.
Exclude large emails from scanning — You can now exclude emails from on-access scanning based on the size of an email.
Block emails from specific IP addresses — You can now blacklist a specific IP address, or range of IP addresses, from sending emails to your organization regardless of the IP address reputation score.
Browser enhancements — Mozilla Firefox 74.0, Google Chrome 142.0 or later, and Microsoft Edge 142.0 or later.
Note
Make sure that you disable the pop-up blocker in the browser settings to access the product web interface.
Other features
Protection from viruses — Scans all email messages for viruses and protects your Exchange server by intercepting, cleaning, and deleting the viruses that it detects. TSME uses advanced heuristic methods and identifies unknown viruses or suspected virus-like items and blocks them.
Filtering file types when enabling TIE — This feature enables you to filter the different file types when enabling TIE.
Rescanning of files — Enables you to resubmit files for scanning during scan failures.
Protection from malicious URLs — Protects your system from malicious URLs. When enabled, TSME scans each URL in the email body, gets the reputation score of the link, compares the score with the defined threshold, and takes appropriate action according to the configuration.
Capability to detect packers and potentially unwanted programs — Detects packers that compress and encrypt the original code of an executable file. It also detects potentially unwanted programs (PUPs), that are software programs written by legitimate companies to alter the security state or privacy state of a computer.
Content filtering — Scans content and text in the subject line or body of an email message and an email attachment. TSME supports content filtering based on regular expressions (regex).
File filtering — Scans an email attachment depending on its file name, type, and size of the attachment. TSME can also filter files containing encrypted, corrupted, password-protected, and digitally signed content.
DLP and compliance — Ability to ensure that email content is in accordance with your organization’s confidentiality and compliance policies. Pre‑defined compliance dictionaries include:
Addition of 60 new DLP and Compliance dictionaries
Support for industry specific compliance dictionaries — HIPAA, PCI, Source Code (Java, C++ etc.)
Improvements to existing phrase based detections.
Reduced false positives, due to enhanced capabilities in detecting non‑compliant content, based on the Threshold score and in combination with the maximum term count (occurrence).
Customize policies for content security and Data Loss Prevention (DLP).
IP reputation — A method of detecting threat from email messages based on the sending server's IP address. IP Reputation Score reflects the likelihood that a network connection poses a threat. IP reputation leverages on Global Threat Intelligence to prevent damage and data theft by blocking the email messages at the gateway based on the source IP address of the last email server. TSME processes the message before it enters the organization by rejecting or dropping the connection based on the IP reputation score.
Advanced on-demand scan — Ability to perform granular‑level on‑demand scan on Exchange Server SE, 2016, and 2019 resulting in faster on‑demand scans. You can schedule on‑demand scans based on these filters; Subject, Attachments, Sender/Recipient/CC, Mail Size, Message ID, Unread items, and Time duration.
Continuity Scan — You can schedule on-demand scanning for the past 365 days using weeks, months, and days filters. For example, if you want to scan items for the past 28 days, enable Continuity scan checkbox and add 28 in the Scan from past days drop-down column.
Background scanning — Facilitates scanning of all files in the information store. You can schedule background scanning to periodically scan a selected set of messages with the latest engine updates and scanning configurations. In TSME, you can exclude mailboxes that you don't want to be scanned.
Product Health Alerts — These are notifications on the status of the product's health. You can configure and schedule these alerts.
Integrate with Trellix ePolicy Orchestrator - On-premises — Integrates with Trellix ePolicy Orchestrator - On-premises to provide a centralized method for administering and updating TSME across your Exchange servers. This reduces the complexity of administrating and updating various systems.
Web-based user interface — Provides a user-friendly web-based interface based on DHTML.
Policy Management — The Policy Manager menu option in the product user interface lists different policies you can set up and manage in TSME.
Centralized scanner, filter rules, and enhanced alert settings — Using scanners, you can configure settings that a policy can apply when scanning items. Using File Filtering rules, you can set up rules that apply to a file name, file type, and file size.
On-demand/time-based scanning and actions — Scans email messages at convenient times or at regular intervals.
Multipurpose Internet Mail Extensions (MIME) scanning — A communications standard that enables you to transfer non-ASCII formats over protocols (such as SMTP) that support only 7-bit ASCII characters.
Quarantine management — You can specify the local database to be used as a repository for quarantining infected email messages.
Auto-update of virus definitions, Extra DATs, and anti-virus engine — Regularly provides updated DAT files and anti-virus scanning engine to detect and clean the latest threats.
Retention and purging of old DATs — Retain old DAT files for periods you define or purge them as needed.
Support for Site List editor — Specify a location from which to download automatic updates for TSME.
Support for Small Business Server — TSME is compatible with Small Business Servers.
Detection reports — Generates status reports and graphical reports that enable you to view information about detected items.
Configuration reports — Summarizes product configuration such as information about the server, version, license status and type, product, debug logging, on-access settings, and on-access policies. You can specify when your server needs to send the configuration report to the administrator.
Denial-of-service attacks detection — Detects additional requests or attacks flooding and interrupting the regular traffic on a network. A denial-of-service attack overwhelms its target with false connection requests, so that the target ignores legitimate requests. TSME considers these three scenarios as Denial-of-service attacks:
Scanning time exceeds the defined time
Nested level exceeds the defined level
Expandable file size limit for archived files exceeds the defined size
Advanced notifications — Forward the quarantined emails for compliance audit to multiple users, based on the detection category.
File Filtering Rules for password-protected files — This feature enables you to separately apply File Filtering Rules for both password-protected files and non password-protected files.
Support for VMware workstation 7.0 or later, and VMware ESX 5.5.
Support for Microsoft Exchange SE, 2016, and 2019.
Important: VSPAI scanning is not applicable from Exchange Server 2013 and later.
Support for proprietary function of InstallShield.
Support for RAR5 files — Supports scanning of RAR5 files in email attachments.