<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Encrypted files on Sandblast agent in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31741#M13850</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;afaik you can block or allow encrypted attachments / files, don't know anything about decryption of those files&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Jun 2018 19:15:56 GMT</pubDate>
    <dc:creator>Vincent_Bacher</dc:creator>
    <dc:date>2018-06-15T19:15:56Z</dc:date>
    <item>
      <title>Encrypted files on Sandblast agent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31740#M13849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please, I need to understand whats happen in Sand Blast Agent with encrypted files protected by a password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Encrypted file are considered malicious and not sent to the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Encrypted file are opened in Threat emulation, but before the emulation is necessary that the receiver user know the &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; password to open the file. Is necessary to put this password in the configuration of the Sanblast agent or&amp;nbsp; in&amp;nbsp;&amp;nbsp;&amp;nbsp; the&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; configuration of the Threat Emulator to open the file during the threat emulation operation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of these is correct? Or there is another one way?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Giancarlo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2018 18:22:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31740#M13849</guid>
      <dc:creator>Giancarlo_Cotta</dc:creator>
      <dc:date>2018-06-15T18:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted files on Sandblast agent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31741#M13850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;afaik you can block or allow encrypted attachments / files, don't know anything about decryption of those files&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2018 19:15:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31741#M13850</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2018-06-15T19:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted files on Sandblast agent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31742#M13851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, but I cannot understand what is the behavior of the Threat Emulation and Threat Extraction with encrypted files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All file protected with a password are considered malicious?&lt;/P&gt;&lt;P&gt;All encrypted files are considered malicious always malicious?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i need to receive password protected file, but I would like to emulate this file before send the file to end user can the Sandblast emulate this file?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2018 19:38:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31742#M13851</guid>
      <dc:creator>Giancarlo_Cotta</dc:creator>
      <dc:date>2018-06-15T19:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted files on Sandblast agent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31743#M13852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding password protected archives there is&amp;nbsp;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;sk112821&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2018 19:43:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31743#M13852</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2018-06-15T19:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted files on Sandblast agent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31744#M13853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Support for encrypted archives exist (by scanning the subject or body of email).&lt;/P&gt;&lt;P&gt;Support for password protected documents (technically encrypted with a password) does not and this is where CP should focus.&lt;/P&gt;&lt;P&gt;TE cannot break the password or encryption but once the file is delivered to the endpoint client and the user enters the password, the behaviour of the file should be analysed from the SandBlast Agent. At this point it doesn't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charris&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 15:50:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31744#M13853</guid>
      <dc:creator>Charris_Lappas</dc:creator>
      <dc:date>2018-06-19T15:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted files on Sandblast agent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31745#M13854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Giancarlo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 19:18:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31745#M13854</guid>
      <dc:creator>Giancarlo_Cotta</dc:creator>
      <dc:date>2018-06-19T19:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted files on Sandblast agent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31746#M13855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How many are the ways to emulate the encrypted archive?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Threat Emulator wait that the user put the password in the encrypted file. Ok, this is a way to emulate the files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In sk112821 I can see that is possible to configure a file with passwords to open certain type of files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose these passwords were previoulsy shared from the sender of the mail with the Threat emulator administrator.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the two ways correct or I'm wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thansk a lot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Giancarlo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 08:26:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31746#M13855</guid>
      <dc:creator>Giancarlo_Cotta</dc:creator>
      <dc:date>2018-06-20T08:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Encrypted files on Sandblast agent</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31747#M13856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The&amp;nbsp;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #333333; font-family: 'Helvetica Neue',Helvetica,Arial,'Lucida Grande',sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;sk112821&lt;/SPAN&gt; discuss about password protected archives only i.e ZIP, not password protected files i.e .docx&lt;/P&gt;&lt;P&gt;In regards to SK112821 yes, you need to supply those interesting words before the emulation. One practice is to have a predefined password set for your communications. This is an issue on management but a workable solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately once a file/archive is password protected/encrypted there are not many options to analyse the content.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2018 11:47:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Encrypted-files-on-Sandblast-agent/m-p/31747#M13856</guid>
      <dc:creator>Charris_Lappas</dc:creator>
      <dc:date>2018-06-20T11:47:04Z</dc:date>
    </item>
  </channel>
</rss>

