The following meta-information is stored about the objects in the quarantine:
: IP address and port of the client receiving the quarantined object.
: The zone that the client belongs to.
: Date when the object was quarantined.
: Detailed description of the verdict.
: The direction the quarantined object was transferred (that is,upload
ordownload
).CF.
: MIME-type of the quarantined object as detected by: File name or URL of the quarantined object.
: A unique identifier of the file in the quarantine.
: The sender address (in case of e-mails).
: The user who tried to access the object belongs to the listed usergroups.
: Kind of the quarantined content:file
,e-mail
, ornewsnet post
.
: The HTTP method (for example,GET
,POST
) in which the quarantined object was detected.CF or PNS).
: The program that quarantined the object (usually: The protocol in which the quarantined object was found.
: Name of the proxy class that requested content vectoring on the quarantined object.
: The envelope recipient addresses of the object (only in SMTP).
: The reason why the object was quarantined (for example, detected as virus, spam, and so on).
CF rule group that was stacked by the proxy.
: The: The scanpath that quarantined the object.
: The envelope sender address of the object (only in SMTP).
: IP address and port of the server sending the quarantined object.
: The zone that the server belongs to.
: ID of the session which requested content vectoring on the quarantined object.
: Size of the object in bytes.
: Indicates if the e-mail is detected as spam.
: The subject of the e-mail.
: The recipient address (in case of e-mails).
: MIME-type of the quarantined object according to its MIME header.
: Name of the user who tried to access (for example, download) the object.
: The decision that caused the object to be quarantined (for example,REJECT
,ACCEPT_QUARANTINE
, and so on): The virus(es) detected in the object.
Naturally, only the information relevant to the specific object is available, for example, an infected file downloaded through HTTP does not have subject, and so on.
Published on June 04, 2020
© 2007-2019 BalaSys
Send your comments to support@balasys.hu