Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SubZer0
Collaborator

Issue downloading original file from Threat Extraction UserCheck link

Hi everyone,

I am experiencing an issue with downloading a file that was processed by the Threat Extraction blade with the action Prevent - Extract potentially malicious content.

When the email attachment was processed, Threat Extraction applied the prevent action and sent the user a notification containing a link to access the original file:

Screenshot 2026-07-14 130243.png

However, when the user clicks the provided link, they receive an error stating they cannot access the file.

My question is: is there a known bug regarding this service, or did I misconfigure something? While reviewing the Threat Extraction blade settings, I didn't notice any configurations specifically related to downloading false-positive files.

Additionally, I would like to know if it is possible to require a password to download these files. I want to prevent just any user from downloading a suspicious file, even if they think it is a false positive.

I also tried to retrieve the original file directly on the gateway using the following command:

scrub send_orig_file <File ID> <Email Address>

And I checked the following directories:

  • /var/log/jail/tmp/scrub

  • $FWDIR/tmp/te

The file was no longer there because the firewall had already deleted it. Was I checking the correct directories?

Thanks in advance for any insights!

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

What version/JHF level are we working with on what appliances?
Is this a cluster and did you check all members?

As far as I know you can't password protect the ability to download files.
At least in the Optimized profile, it will only allow this if Threat Emulation says the file is safe.
It can also be disabled entirely, either in the Threat Prevention profile:

image.png

or, if you're using Autonomous Threat Prevention:

image.png

SubZer0
Collaborator

I have an issue with a Check Point 9400 running an R81.20 Jumbo Hotfix Take 127 cluster. I have checked both cluster members. The current configuration is:

Screenshot 2026-07-15 123825.png

Screenshot 2026-07-15 123832.png

 

0 Kudos
PhoneBoy
Admin
Admin

This SK suggests a different directory to look at: https://support.checkpoint.com/results/sk/sk114629
Otherwise I suggest getting TAC involved.

SubZer0
Collaborator

I can send file with command scrub send_orig_email {<Email ID or Reference Number>} all.

I open TAC. Thanks. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events