<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remove Hyperlink from the Body of the mail in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-Hyperlink-from-the-Body-of-the-mail/m-p/49944#M13498</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we know that one of the Threat Extraction features offer removal of&amp;nbsp;Hyperlink from the attachment of the mail. Similarly is it possible to remove the hyperlink from the body of the mail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If threat Extraction cannot do this can any other blade offer this feature?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Apr 2019 16:02:26 GMT</pubDate>
    <dc:creator>amith_rao</dc:creator>
    <dc:date>2019-04-05T16:02:26Z</dc:date>
    <item>
      <title>Remove Hyperlink from the Body of the mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-Hyperlink-from-the-Body-of-the-mail/m-p/49944#M13498</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As we know that one of the Threat Extraction features offer removal of&amp;nbsp;Hyperlink from the attachment of the mail. Similarly is it possible to remove the hyperlink from the body of the mail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If threat Extraction cannot do this can any other blade offer this feature?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 16:02:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-Hyperlink-from-the-Body-of-the-mail/m-p/49944#M13498</guid>
      <dc:creator>amith_rao</dc:creator>
      <dc:date>2019-04-05T16:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Hyperlink from the Body of the mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-Hyperlink-from-the-Body-of-the-mail/m-p/49999#M13499</link>
      <description>&lt;P&gt;Start here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109699&amp;amp;partition=Advanced&amp;amp;product=Mail" target="_self"&gt; ATRG: Mail Transfer Agent (MTA)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 15:42:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-Hyperlink-from-the-Body-of-the-mail/m-p/49999#M13499</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-04-06T15:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Hyperlink from the Body of the mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-Hyperlink-from-the-Body-of-the-mail/m-p/50015#M13500</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Heiko&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The ATRG helps us understand how MTA works and the blades which can leverage this feature.&lt;/P&gt;&lt;P&gt;Supported blades for MTA feature are as follows: Threat Emulation, Threat Extraction, Anti-virus(R80.10 and above) Anti-Spam &amp;amp; E-mail Security.&lt;/P&gt;&lt;P&gt;But again my requirement is to scrap all the hyperlinks from the body of the Mail irrespective of whether the hyperlinks are genuine or not.&lt;/P&gt;&lt;P&gt;I am pretty much sure that the Threat extraction and&amp;nbsp;Threat Emulation can do this on the attachments but not on the body of the mail.&lt;/P&gt;&lt;P&gt;At the same time, Anti-virus and Anti-bot blades can scan the mail body and only quarantine the Hyperlink found malicious.&lt;/P&gt;&lt;P&gt;But is there any option to quarantine all the hyperlink from mail body whether it is genuine or not?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Amith&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 19:09:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-Hyperlink-from-the-Body-of-the-mail/m-p/50015#M13500</guid>
      <dc:creator>amith_rao</dc:creator>
      <dc:date>2019-04-06T19:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Hyperlink from the Body of the mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-Hyperlink-from-the-Body-of-the-mail/m-p/50083#M13501</link>
      <description>&lt;P&gt;Hi Amith,&lt;/P&gt;&lt;P&gt;Refer the below link for more details.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/SandBlast-Network/SandBlast-and-links-inside-email/td-p/15798" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/SandBlast-Network/SandBlast-and-links-inside-email/td-p/15798&lt;/A&gt;&lt;/P&gt;&lt;P&gt;As I summarize base on the discussion.&lt;/P&gt;&lt;DIV&gt;In MTA, Threat Emulation work only if that URL end with any file extension, like&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://abc.com/xyz.pdf" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;http://abc.com/xyz.pdf&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;also&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://abc.com/" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;http://abc.com&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;leads to the PDF file to download (xyz.pdf)&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;It did not scan if it's not to leads any PDF or any known extension like simple&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://abc.com/" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;http://abc.com&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;When enabling AV in MTA then URL reputation is checked over MTA base on the risk level. So if the risk level is&amp;nbsp; 80 or below 80 then that malicious URL is not blocked even that the malicious URL have severity": "Medium", "confidence": "High".&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;As on the above scenario, URL is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;bypass&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;but If the customer is using Checkpoint URL Filtering then when the user is open that malicious link its BLOCK by Checkpoint URL Filtering. Because CP URL filtering is working base on severity and confidence level, not by Risk level.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;YES we can remove the malicious link from mail body but not sure about remove the all hyperlink that may genuine or not.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thank You&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 16:43:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remove-Hyperlink-from-the-Body-of-the-mail/m-p/50083#M13501</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2019-04-08T16:43:25Z</dc:date>
    </item>
  </channel>
</rss>

