Email continues to be a top incursion vector for attackers. As a result, organizations need to gain better visibility into their email, which is the most critical and exposed control point. Understanding threat actors and the email threat landscape has become imperative for customers today, as they are looking to quickly investigate, correlate, and respond to threats.
Symantec Advanced Threat Protection for Email already provides deep visibility into the threat landscape with Indicators of Compromise (IOCs) on malicious emails such as file hashes and URLs as well as attacker information such as sender IPs & sender countries. This intelligence can be seamlessly ingested into third-party Security Incident and Event Management tools (SIEM) such as Splunk, IBM QRadar, and HP ArcSight, which enables Security Operations Center (SOC) teams to investigate and respond to advanced email attacks. Customers are leveraging this information for use cases such as correlating malicious file hash information from emails with their endpoints, feeding malicious links into their Web proxies to gain insight into attackers, and increasing protection by understanding targeted threats against their organizations.
Last month, we announced new Business Email Compromise protection and deeper visibility into advanced email attacks. Today, we are excited to announce the launch of new APIs as part of our Advanced Email Security Analytics, which provide deep visibility into both clean and malicious emails by extending our intelligence to all emails scanned by our Symantec Email Security.cloud service. These APIs enable organizations to:
Over the next couple of months, we will release an updated version of our free Splunk application that will leverage these new data sources to provide enhanced advanced analytics at your fingertips.
Getting Started
This feature is available to Symantec Advanced Threat Protection for Email customers today. To enable the data feeds, please refer to settings section under Advanced Threat Protection:Email in Email Security.cloud portal. You can also download our admin guide that provides detailed information about the data points provided and sample Python scripts to get started quickly.
Join our webcast on August 30 to learn more about the latest capabilities and see them in action!