Content & Malware Analysis

 View Only
  • 1.  CAS Unable to Analyze the URLs

    Posted Jun 23, 2020 01:35 PM
    <enduser-root ng-version="8.2.14" _nghost-jjg-c0=""><enduser-esd _nghost-jjg-c6=""><enduser-frame-layout class="mat-typography" _ngcontent-jjg-c6="" _nghost-jjg-c7="">
    <enduser-mycases class="ng-star-inserted" _nghost-jjg-c15="">
    <as-split class="as-horizontal as-transition as-init" _ngcontent-jjg-c15="" direction="horizontal" guttercolor="grey" usetransition="true" _nghost-jjg-c16=""><as-split-area class="as-split-area" _ngcontent-jjg-c15="">
    <enduser-tickets-detail class="overflow-auto full-height ng-star-inserted" _ngcontent-jjg-c15="" fxflex="12 1 0" _nghost-jjg-c19=""><mat-tab-group class="tickets-tab mat-elevation-z4 full-height mat-tab-group mat-primary ng-star-inserted" mat-stretch-tabs="" _ngcontent-jjg-c19="">
    <mat-tab-body class="mat-tab-body ng-tns-c34-66 mat-tab-body-active ng-star-inserted" id="mat-tab-content-2-0" role="tabpanel" aria-labelledby="mat-tab-label-2-0">
    <enduser-dynamic-case-details-fields class="ng-star-inserted" _ngcontent-jjg-c19="" _nghost-jjg-c30="">
    Hi. We have Symantec Messaging Gateway (SMG) integrated with CAS which is also doing on-box Sandboxing. The integration is working fine and CAS is analyzing the email attachments which SMG is sending to it as part of this integration. However if there are any URLs in the body of the email which is being sent to CAS by SMG, then those URLs in the email body are not being analyzed or scanned by SMG.

    We would like to know if this is an expected behavior and it is working as designed that CASMA will not scan or analyze any URLs in the body of the email which is sent to it by SMG. 
    </enduser-dynamic-case-details-fields>
    </mat-tab-body>
    </mat-tab-group></enduser-tickets-detail>
    </as-split-area></as-split>
    </enduser-mycases>
    </enduser-frame-layout></enduser-esd></enduser-root>

    ------------------------------
    Symantec Enthusiast
    ------------------------------


  • 2.  RE: CAS Unable to Analyze the URLs

    Posted Jun 26, 2020 01:20 PM
    Edited by Kostas Jun 26, 2020 01:21 PM

    Hello 

    For that you have Symantec Threat Isolation Platform (STIP) that integrates with SMG.
    Modified urls from SMG in the form https://stip.mydomain.com/?url=https://www.cnn.com are opened through web isolation.

    BR,
    Kostas