3CX DLL-Sideloading attack: What you need to know
Hello all,
I am currently starting to use Sophos Central Mail. First tests with the end-user quarantine have shown that released mails sometimes end up in the quarantine again after being released by another policy.
Here is the process I am observing:
1. mail (with unscannable attachment) comes in and is scanned2. email security module quarantines mail because attachment can't be scanned3. user gets quarantine summary4. user releases the mail
up to here everything as I expect it but then:
5. data protection module detects the released mail as unscannable and moves it back to quarantine
Maybe I missed the point or it is intentional but my wish is that a deliberately released mail cannot be quarantined by another scan.
Maybe someone can help me.
Many greetingsStephan
Hello prifesport,Thank you for reaching out to the community, This is a known behavior in some cases. The issue XGE-19926 seems to be related. In addition, we would need to confirm what was the reason for quarantine in the first place, as well as what was the reason in the second place. There may be two reasons for quarantining it again after releasing. According to the known issue, the first cause is BULK and the second one is DLP, so what was the reason you noticed?
Thanks & Regards,_______________________________________________________________
Vivek Jagad | Team Lead, Global Support & Services
Sophos Community | Product Documentation | Sophos Techvids | SMSIf a post solves your question please use the 'Verify Answer' button.
Hi Vivek,
Thank you for your quick response.
the first action was due to unscannable content.
With the second event I only see that it was the data control. But there is only an attachment filter included, so it could have been only the attachment.
Hopefully this information will help.
Regards
Stephan
Hey prifesport,Alright, thank you for the update, this does not seems to be related to the known issue mentioned !I would suggest to log a support request and get this further investigated !!