cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3357
Views
0
Helpful
3
Replies

ESA file analysis (AMP)

Greg Dickinson
Level 1
Level 1

I've read the docs and searched around, and I can't get a definite answer to a question presented to me.  If we have the AMP policy enabled, and have it configured to send "Pending Analysis" messages to the quarantine - will the messages be released immediately upon receiving a verdict, or only when the time limit expires?  Also, is it possible to send a message to the original recipient if their message is "pending analysis", so we don't get "Where is my email?" tickets?

 

Thanks in advance... 

2 Accepted Solutions

Accepted Solutions

marc.luescherFRE
Spotlight
Spotlight

The process is as follows :

 

AMP checks in prescan phase for local defined rules 

AMP moves the file into the quarantine : File Analysis, the defined Default Action "30 Min in our case" defines when the email will be Relased to the intended end user, no matter if there was already a verdict or not

AMP can use MAR (Message Auto Remediation) to remove such emails should the verdict later become malicious.

 

You can not sent a message to the users when the email gets into the quarantine queue but based one experience 99% of all emails will be released to end users in less then 5 Min, so that is a good value for security.

 

I hope that helps

 

-Marc

View solution in original post

OK, so if the verdict is received before the 30 minute timeout, then the message is released immediately, otherwise it is released after 30 minutes regardless.  Thanks

View solution in original post

3 Replies 3

marc.luescherFRE
Spotlight
Spotlight

The process is as follows :

 

AMP checks in prescan phase for local defined rules 

AMP moves the file into the quarantine : File Analysis, the defined Default Action "30 Min in our case" defines when the email will be Relased to the intended end user, no matter if there was already a verdict or not

AMP can use MAR (Message Auto Remediation) to remove such emails should the verdict later become malicious.

 

You can not sent a message to the users when the email gets into the quarantine queue but based one experience 99% of all emails will be released to end users in less then 5 Min, so that is a good value for security.

 

I hope that helps

 

-Marc

OK, so if the verdict is received before the 30 minute timeout, then the message is released immediately, otherwise it is released after 30 minutes regardless.  Thanks

correct, you can further reduce the retention period from 30 min to 15 min if you have a business need but would advise against if it can be avoided.