Check Point Harmony Email & Collaboration malware attachments in email received by user
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Goal
Detects when emails containing malware attachments are received from an external sender, which may indicate a malware distribution campaign or a compromised sender attempting to spread malicious payloads.
Strategy
This rule monitors inbound emails and raises an alert when emails with malware attachments originate from an external sender, suggesting a targeted attack or widespread malware distribution.
Triage and Response
- Review the sender email address
{{@event.entity.entity_payload.from_email}} and analyze the malware attachments. - Quarantine or delete the detected emails to prevent users from opening malicious attachments.
- Notify affected users and begin a security incident response process to investigate engagement with attachment and endpoint activity.