<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Email Link Analysis - does it look at all emails? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343893#M86060</link>
    <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Fri, 14 Aug 2020 11:48:19 GMT</pubDate>
    <dc:creator>joecbrown</dc:creator>
    <dc:date>2020-08-14T11:48:19Z</dc:date>
    <item>
      <title>Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/342685#M85861</link>
      <description>&lt;P&gt;I am curious to know if the organization I work at gets a blast email to 500 employee's from an external B2B marketer does the wildfire analysis get performed on all 500 identical emails or does it simply do it once knowing the email and links are identical.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 13:35:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/342685#M85861</guid>
      <dc:creator>joecbrown</dc:creator>
      <dc:date>2020-08-07T13:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/342697#M85864</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/151532"&gt;@joecbrown&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per my knowledge WF maintains trusted domain list and it will examine the external email address only once.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 16:15:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/342697#M85864</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-08-07T16:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/342713#M85867</link>
      <description>&lt;P&gt;Actually yes, the firewall is doing the analysis for every email. It does not really care about the url, it simply forwards it to wildfire - in batches of 200 URLs per upload or all 2 minutes - depending on which limit is hit first. About the list of trusted sites I am not sure, as theoretically there is nothing like trusted site. On every website there is the potential risk that it gets hacked and will be used to host malware or exploit kits. But at least I think, there is a timer that a website is not ddos'ed by wildfire and only scanned for example max. once per hour or day. About a local check if the urls are identical, &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;could you say something about this? But often the links in such mass-emails aren't identical, every link is different to track which recepient clicks on the url.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 18:03:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/342713#M85867</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-07T18:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/342761#M85872</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp; and others..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From the official documentation on WildFire email analysis..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/wildfire/9-0/wildfire-admin/wildfire-overview/wildfire-concepts/email-link-analysis" target="_blank"&gt;https://docs.paloaltonetworks.com/wildfire/9-0/wildfire-admin/wildfire-overview/wildfire-concepts/email-link-analysis&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It states:&lt;/P&gt;
&lt;P&gt;"&lt;SPAN style="font-family: inherit;"&gt;WildFire visits submitted links to determine if the corresponding web page hosts any exploits or displays phishing activity. A link that WildFire finds to be malicious or phishing is:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Recorded on the firewall as a WildFire Submissions log entry. The WildFire analysis report that details the behavior and activity observed for the link is available for each WildFire Submissions log entry. The log entry also includes the email header information—email sender, recipient, and subject—so that you can identify the message and delete it from the mail server, or mitigate the threat if the email has been delivered or opened.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;
&lt;DIV&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;Added to PAN-DB and the URL is categorized as malware.&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;DIV class="p"&gt;
&lt;DIV&gt;The firewall forwards email links in batches of 100 email links or every two minutes (depending on which limit is hit first). Each batch upload to WildFire counts as one upload toward the upload per-minute capacity for the given firewall&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;
&lt;DIV&gt;Firewall Forwarding Capacity by Model&lt;/DIV&gt;
&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(PAN-OS&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" title="" href="https://docs.paloaltonetworks.com/wildfire/8-1/wildfire-admin/submit-files-for-wildfire-analysis/firewall-file-forwarding-capacity-by-model.html" target="_blank" rel="noopener" data-scope="external" data-format="dita" data-type=""&gt;8.1&lt;/A&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" title="" href="https://docs.paloaltonetworks.com/wildfire/9-0/wildfire-admin/submit-files-for-wildfire-analysis/firewall-file-forwarding-capacity-by-model.html" target="_blank" rel="noopener" data-scope="external" data-format="dita" data-type=""&gt;9.0&lt;/A&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" title="" href="https://docs.paloaltonetworks.com/wildfire/9-1/wildfire-admin/submit-files-for-wildfire-analysis/firewall-file-forwarding-capacity-by-model.html" target="_blank" rel="noopener" data-scope="external" data-format="html" data-type=""&gt;9.1&lt;/A&gt;). If a link included in an email corresponds to a file download instead of a URL, the firewall forwards the file only if the corresponding file type is enabled for WildFire analysis.&lt;SPAN style="font-family: inherit;"&gt;"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN style="font-family: inherit;"&gt;I hope this helps a little..&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 07 Aug 2020 20:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/342761#M85872</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-08-07T20:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/342888#M85886</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;My question was more about if the firewall already does a local check for the urls? Or does it - in the case like in this topic - upload 500 times exactly the same URL to wildfire if there are 500 incoming emails with this one URL?&lt;/P&gt;</description>
      <pubDate>Sun, 09 Aug 2020 10:52:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/342888#M85886</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-09T10:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343260#M85944</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;That is what I am trying to understand as well. &amp;nbsp;If 500 people in my organzition all receive the same email with the same url &lt;A href="http://www.website.com/page123" target="_blank"&gt;http://www.website.com/page123&lt;/A&gt;. &amp;nbsp;Is that URL submitted 500 times and scanned 500 times or does it scan that URL once?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 11:59:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343260#M85944</guid>
      <dc:creator>joecbrown</dc:creator>
      <dc:date>2020-08-11T11:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343285#M85949</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/151532"&gt;@joecbrown&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When there are 500 of the exact same link.. I&amp;nbsp; would like to think that it would count them as one, but I will ask the experts about this and see what they are able to tell me.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will respond as soon as I have an answer.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 14:02:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343285#M85949</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-08-11T14:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343745#M86037</link>
      <description>&lt;P&gt;OK,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/151532"&gt;@joecbrown&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp; and everyone else.. found the info..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Actually I was able to get the details from people who looked at the code, and other detailed info.. and it looks like there will be&amp;nbsp;&lt;SPAN&gt;500, because each one comes from a different email header and we produce separate reports with the specific session information associated with the SMTP, IMAP or POP3 session. So, all links are sent to the cloud at this time, duplicate or not.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 14:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343745#M86037</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-08-13T14:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343751#M86039</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;This makes sense, as the URL is only one of the different attributes contained in wildfire report.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 15:06:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343751#M86039</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-13T15:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343753#M86040</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks for this great info!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 15:14:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343753#M86040</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-08-13T15:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343754#M86041</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23567"&gt;@jdelio&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;So, all links are sent to the cloud at this time, duplicate or not.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Hmn ... what if now all these attributes are the same? Either if the same email really was sent 500 times or if the same email was sent to 500 recipients in bcc. In this case the firewall would only show the actual recipient in the to field of the email but nothing about bcc. But I assume even then there it will be forwarded to wildfire 500 times.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 15:22:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343754#M86041</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-08-13T15:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343893#M86060</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 11:48:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343893#M86060</guid>
      <dc:creator>joecbrown</dc:creator>
      <dc:date>2020-08-14T11:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Email Link Analysis - does it look at all emails?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343908#M86063</link>
      <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;, it would seem that it treats them individually, so yes, 500 links to WildFire.. In batches of 100.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Aug 2020 14:57:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/email-link-analysis-does-it-look-at-all-emails/m-p/343908#M86063</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2020-08-14T14:57:03Z</dc:date>
    </item>
  </channel>
</rss>

