This guide will walk you through the process of investigating emails in your domain.
STEP ONE:
Sign into your Cloud Access Monitor Instance.
STEP TWO:
Navigate to the Audit & Control page, and select the Name of your desired Cloud Environment. (Global Views will show all accounts in your domain, while filtered views will show only users for that view)
STEP THREE:
Select the Emails Tab across the top of the screen.
STEP FOUR:
The Email Messages Tab will display all emails found in your environment within the last 7 days.
Note: Only Emails Containing an Attachment or Risk will be searchable here.
Information about each message will be displayed in the results box.
Subject: The subject of the email.
Attachments: The number of attachments in the email.
Attachment Size: The total size of the attachments.
Sender: The account that sent the email.
Recipient: The recipients the email was sent to.
Mailbox: The mailboxes in your domain that contain the email.
Email sent on: The date and time the email was sent.
Actions: Actions you can take against the email.
-Quarantine: Put the email in a safe place to be examined.
-Download: Download the email to further inspect it.
-Delete: Delete the email.
STEP FIVE:
There is a Search Bar located above the results menu, the search bar has eight search parameters to chose from. Select the Down Arrow to change search parameters.
Subject: Search by the subject of the email that was sent.
Attachment Name: Search by the name of an attachment.
Content: Search by content found within emails.
Sender: Search by the sender of an email.
Recipient: Search by recipients of an email.
Mailbox: Search by specific user mailboxes.
Domain: Search by a specific domain name ex: managedmethods.com
Organizational Unit: Search only mail found within a specific organizational unit.
STEP SIX:
On the right side of the screen you will find the Filter button. Filters will allow you to find all emails that contain user defined parameters.
Email Date: A user defined date range.
Quarantine Status: Search either quarantined or unquarantined emails.
Messages Sent: The direction of the email, incoming, outgoing, or within domain.
Risky Messages: Messages that contain risk, such as a PCI violation.
Malicious Messages: Messages that contain malware files.
Email Attachments: Search for messages that contain, or don't contain attachments.
Trashed Messages: Messages that are in a trashcan.
Attachment Size: Sort by the size of the attachments.
STEP SEVEN:
Once you have searched or filtered to see the emails you desire, there are many different ways to learn more about the emails under investigation.
Clicking The Email Subject:
By clicking the subject of the email, a popup will appear displaying information about the email.
Basic Tab:
Sender: Who sent the email
Domain: The domain the email is in.
Subject: The subject of the email.
Internal Domain: A list of recipients within your domain that have the email.
External Domain: A list of recipients outside your domain who have received the email.
A list of the attachments associated with the email, name and size are displayed, and the Download icon allows you to download the attachment for further investigation.
Risk Details (Click Risk Icon):
The Risk tab will display information about the type of risk that was caught. This does not include malware or phishing urls.