Get access to immediate incident response assistance.
Eliminate active threats with 24/7 threat detection, investigation, and response.
Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.
Advance your cybersecurity program and get expert guidance where you need it most.
Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.
Prevent unauthorized access and exceed compliance requirements.
Stop email threats others miss and secure your organization against the #1 ransomware attack vector.
Prepare for the inevitable with 24/7 global breach response in-region and available on-site.
Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.
Before proceeding with the following you will need to have analyzed the message (.mml) in question for unique text that you can search for in the body. It can be different from environment to environment, but in the following example we knew what the Helo Name of our internal mail server was and what the subject of an email that was sent out by the OOA was. We also knew that if it had both of these in the Message Body and/or the Message Text then we would know that we could block only these types of NDRs.
Example: Rule: Block OOA NDRs When a message arrives Where message is incoming Where message triggers text censor script(s) 'Block OOA NDRs' Move the message to 'OOA NDRs'
To contact Trustwave about this article or to request support: