InterScan Messaging Security scans the file attachment inside the email when the Attachment Filter option is enabled. To enable the Attachment Filter:
- Log in to the InterScan Messaging Security product console.
-
Go to Policy > Policy List > Add > Others to create a new policy.
-
Under Step 1: Select Recepients and Senders, choose your preferred policy route type from the This rule will apply to dropdown list:
- incoming messages
- outgoing messages
- both incoming and outgoing messages
- POP3
- all messages
-
Specify the recipients and senders based on the selected policy route type:
- For incoming messages, specify the recipient’s address that is in range of the internal addresses. For example, internal address is imsstest.com and valid recipients include jim@imsstest.com and bob@imsstest.com.
- For outgoing messages, specify the sender’s address that is in range of the internal addresses. For example, internal address is imsstest.com and valid senders include jim@imsstest.com and bob@imsstest.com.
- For both incoming and outgoing messages, the rule applies to senders or recipients that match the mail address. Use the asterisk wildcard when specifying an email address.
- For POP3, the route cannot be configured because it applies to all POP3 routes.
- For all messages, the rule applies to messages from any sender to any recipient.
- Click Next.
-
Under Step 2: Select Scanning Conditions, tick the True file type or the Name or extension or both check boxes on the Attachment section to filter EXE files.
Select attachment type to filter EXE files.
- Click the Name or extension link.
-
Tick the File extensions to scan (recommended) check box and select only EXE.
- Select Save.
-
Click the True file type link and select EXE from the Executable dropdown list.
- Click Save and then choose Next.
-
Under Step 3: Select Actions, you may choose from the following options:
- Do not intercept messages
This allows you to deliver the message. - Quarantine to
This enables you to quarantine the email.
Select Quarantine to in order to quarantine the mails with EXE attachments.You may also add more actions using one or both of the following options under the Modify section:
- Delete attachment
This prevents the attachment from being delivered. - Insert stamp in body
This adds a stamp to inform the user that a security violation was triggered.
- Do not intercept messages
- Click Next.
-
Under Step 4: Name and Order, fill out the Rule Name and Order Number fields for this rule.
- Click Save.
For the Order Number, you would need to place this rule right after the Global antivirus rule.
In this approach, in case there are undetected EXE files, this rule would do the quarantine action and the email sample can be downloaded for submission to Trend Micro Technical Support.
To download quarantined emails from this rule, go to Mail Areas & Queues > Query and type the Rule name you created. Adjust the date range if necessary and click Display Log.