Showing results for 
Search instead for 
Did you mean: 
Create a Post

Threat Extraction - click here location


what are you folks using as Main URL to allow users to get the original attachments?

When Threat Extraction is active, you can configure it so that users can get the original attachment by clicking "here" in the banner that they see in the mail.

The configuration for the target of "here" is not done in the Threat Extraction config settings but under "UserCheck" in the gateway configuration.

I was using a FQDN that points to the LAN interface of the firewall gateway but that of course doesn't help users external of the gateway (like home users, or on mobile devices).

So should we use an external URL? What are you using? Does this have security implications? 

UserCheck is also used for other things, should we expect a new issue?


0 Kudos
2 Replies

Re: Threat Extraction - click here location

This and more can be found in sk114806: ATRG: Threat Emulation

0 Kudos

Re: Threat Extraction - click here location

I know that sk but I must be looking over the exact info. Can you be more specific please?

0 Kudos