baruwaproject / baruwa2

Baruwa 2.0
http://www.baruwa.org
GNU General Public License v3.0
21 stars 9 forks source link

New feature: blocking policy information #76

Closed mijnsleutel closed 8 years ago

mijnsleutel commented 8 years ago

Hi,

We have some customers that hit the default content protection policy for files. If we look at the log line where it shows protected, there is no easy way to see which policy produced that deny. Maybe after the infected Y, show the regular expression that did actual trigger that deny.

-TY

akissa commented 8 years ago

Am not sure i understand the request fully, can you please post a log extract

mijnsleutel commented 8 years ago

We have mailes that are marked as infected due file policies. But in the details we cannot easy see which rule did actually trigger the mail. It is marked as infected, and no more information.

mijnsleutel commented 8 years ago

for example, email with attachment: p16-02141.zip got marked as infected. But what rule did actually marked that one as infected. The content inside is regular valid content.

akissa commented 8 years ago

Implemented, will be part of the next update