Detected risk is potential danger exhibited by a suspicious email message.
Deep Discovery Email Inspector assesses email message risk using multi-layered threat analysis. Upon receiving an email message, Deep Discovery Email Inspector email scanners check the email message for known threats in the Trend Micro Smart Protection Network and Trend Micro Advanced Threat Scanning Engine. If the email message has unknown or suspicious characteristics, the email scanners send file attachments and embedded URLs to Virtual Analyzer for further analysis. Virtual Analyzer simulates the suspicious file and URL behavior to identify potential threats. Deep Discovery Email Inspector assigns a risk level to the email message based on the highest risk assigned between the Deep Discovery Email Inspector scanners and Virtual Analyzer.
For details about how Deep Discovery Email Inspector investigates email messages, see A New Solution.
Email Message Risk Levels
The following table explains the email message risk levels after investigation. View the table to understand why an email message was classified as high, medium, or low risk.
Risk Level |
Description |
---|---|
High |
A high-risk email message contains:
|
Medium |
A medium-risk email message contains:
|
Low |
A low-risk email message contains:
|
No risk |
A no-risk email message:
|
Unrated |
An unrated email message falls under any of the following categories:
|
Unavailable |
Deep Discovery Email Inspector does not assign a risk level to a spam/graymail message or an email message with content violation or DLP incidents. |
Virtual Analyzer Risk Levels
The following table explains the Virtual Analyzer risk levels after object analysis. View the table to understand why a suspicious object was classified as high or low risk.
Risk Level |
Description |
---|---|
High |
The object exhibited highly suspicious characteristics that are commonly associated with malware. Examples:
|
Low |
The object exhibited mildly suspicious characteristics that are most likely benign. |
No Risk |
The object did not exhibit suspicious characteristics. |