Quarantine Parent topic

TippingPoint Advanced Threat Protection for Email quarantines suspicious email messages that meet certain policy criteria. View details about an email message before deciding whether to delete the email message or release it to the intended recipients.
Before deciding which action to perform, query the email messages that TippingPoint Advanced Threat Protection for Email quarantined.
Perform any of the following actions:
  • Search for quarantined messages based on a variety of criteria
  • Learn more about malicious file attachments and URLs
  • Release or delete quarantined messages

Viewing Quarantined Messages Parent topic

Procedure

  1. Go to DetectionsQuarantine.
  2. Specify the search criteria.
  3. Press ENTER.
    All email messages matching the search criteria appear.
  4. View the results.
    Header
    Description
    investigate_icon.jpg
    Investigate the email message to learn more about potential threats.
    Detected
    View the date and time that the suspicious email message was first detected and quarantined in TippingPoint Advanced Threat Protection for Email.
    Note
    Note
    There is a short delay between when TippingPoint Advanced Threat Protection for Email receives an email message and when the email message appears on the Quarantine screen.
    Risk Level
    View the level of potential danger exhibited in a suspicious email message. For details, see Detected Risk.
    Recipients
    View the detected message recipient email addresses.
    To
    View the primary recipient email address in the email header.
    Sender
    View the sending email address of the detected message.
    From
    View the author email address in the email header.
    Email Subject
    View the email subject of the suspicious email message.
    links_icon.jpg
    View the number of email messages with embedded malicious links.
    attachments_icon.jpg
    View the number of email messages with malicious file attachments.
    Threat
    View the name and classification of the discovered threat. For details, see Threat Type Classifications.

Quarantine Search Filters Parent topic

The following table explains the basic search filters for querying the quarantined email messages. To apply advanced filters, see Applying Advanced Filters.
To view the quarantine, go to DetectionsQuarantine.
Note
Note
Search filters do not accept wildcards. TippingPoint Advanced Threat Protection for Email uses fuzzy logic to match search criteria to email message data.
Filter
Description
Risk level
Select All or the email message risk level.
Recipient
Specify one or more recipient email addresses. Use a semicolon to separate multiple recipients.
Period
Select a predefined time range or specify a custom range.

Investigating a Quarantined Email Message Parent topic

Procedure

  1. Search for the email message.
  2. Click the arrow next to the email message in the table.
    The table row expands with more information.
  3. Discover the email message details.
  4. Take action upon the quarantined message.
    • Leave the message in the quarantine.
      Note
      Note
      Quarantined messages purge based on the settings configured on the Storage Maintenance screen.
    • Click delete_icon.jpg Delete to purge the email message from the quarantine.
    • Click release_icon.jpg Release to deliver the email message.

Quarantined Message Details Parent topic

The following table explains the email message details viewable after expanding the search results.
Field
Description
Overview
View the message ID, recipients, and source IP address of the email message to understand where the message came from and other tracking information.
Attachments
Get information about any files attached to the email message, including the file name, password, file type, risk level, the scan engine that identified the threat, and the name of detected threats.
Links
Get information about any embedded suspicious URLs that appeared in the email message, including the URL, site category, risk level, the scan engine that identified the threat, and the name of detected threats.
Analysis Reports
View and in-depth PDF or HTML analysis report about this email message, including suspicious attachments or links, notable characteristics, callback destinations, and dropped or downloaded files.
Forensics
Get more information about this email message for further analysis. Download the email message or safely download the email message as an image.
Global Intelligence
Click View in Threat Connect to get correlated information about suspicious objects detected in your environment and threat data from the Trend Micro Smart Protection Network, which provides relevant and actionable intelligence.
Message Source
View the email message header content.