heroui logo

Proofpoint Virus Detected

Panther Rules

View Source
Summary
The Proofpoint Virus Detected rule is designed to alert security teams when a virus is detected in emails that cannot be disinfected. The rule is triggered under specific conditions: when emails are quarantined into the Virus folder, when the 'notcleaned' quarantine rule is applied to them, or when they have a malware score of 95 or higher. This is crucial for early detection of potential threats in email communications, which can often lead to malware infections or other security breaches. The status of the rule is experimental, indicating that it may still be subject to adjustments and improvements based on deployment experiences. The associated severity level is high, which underscores the importance of rapid response to detected threats. The rule directly helps prevent malware from reaching user endpoints by enforcing quick containment measures once a virus detection is logged.
Categories
  • Cloud
  • Endpoint
  • Web
  • Application
Data Sources
  • User Account
  • Process
  • Application Log
  • Network Traffic
  • File
ATT&CK Techniques
  • T1566
  • T1204
Created: 2026-02-12