ATSE Detections and Deep Discovery Advisor Parent topic

IMSS leverages ATSE to determine which messages are sent to Deep Discovery Advisor. When enabled, ATSE provides an additional layer of protection against advanced threats, such as document exploits and other threats used in targeted attacks.
ATSE detections are identifiable through the prefixes HEUR and EXPL. If the detection name contains one of these prefixes, IMSS:
  • Sends the entire message (including attachments) to Deep Discovery Advisor for further analysis.
  • Logs the detection as a Probable advanced threat.
Deep Discovery Advisor assigns a risk level to each analyzed message. IMSS queries this risk level approximately 15 minutes after sending the message to Deep Discovery Advisor. After receiving the risk level, IMSS logs the detection as a Probable advanced threat or an Analyzed advanced threat based on the risk level and the security level that you select on the IMSS management console.
Note
Note
If IMSS does not receive a risk level, or if the risk level returned is invalid, IMSS logs the detection as a Probable advanced threat.