LevelBlue Completes Acquisition of Cybereason. Learn More
Get access to immediate incident response assistance.
To detect an empty zip file, as a top level attachment,create a rule similar the following:
Standard Rule: EmptyZip When a message arrives Where the message is addressed to or from any user Where message attachment is of type 'ZIP' And where number of attachments is less than '2' Move the message to 'Suspect'
Ensure that where number of attachments is less than '2' is set to use Top level and all extracted attachments.
where number of attachments is less than '2'
To contact Trustwave about this article or to request support: