Documentation Index

Fetch the complete documentation index at: https://docs.trustifi.com/llms.txt

Use this file to discover all available pages before exploring further.

Threat Response Introduction

Prev Next

Overview

Trustifi's Threat Response system allows you to scan emails that already exist in your users' mailboxes, locate emails according to specific indicators, and perform different actions on emails that match your search criteria.

Requirements

Before performing a Threat Response action, ensure the following prerequisites are met:

1. Microsoft Exchange Integration

  • Your Trustifi plan must be integrated with your Exchange server

  • To enable: Navigate to the Inbound Integrations page (Inbound Management > Plan Settings > Integrations) and click on “Microsoft Exchange

2. Office 365 Mailboxes

  • The mailbox(es) you want to scan must be connected to Office 365

3. Protected Mailboxes

  • The mailbox(es) must be "Protected" by Trustifi

  • To verify: Navigate to the Mailbox Management page (Inbound Management > Mailbox Management) and check the protection status column (displays "Protected" or "Exposed")

When To Use

Remove Recent Threats

  • Remove any threat or suspicious email that may have recently found its way to your users' inboxes

Post-Connection Cleanup

  • For organizations that have just connected to Trustifi's inbound security, Threat Response can perform a general scan of existing user mailboxes to find various malicious content or spam

Emerging Threat Detection

  • If information about a new type of malware or phishing attack has surfaced, Threat Response can be used to check if any existing emails contain this type of threat

Bulk Email Removal

  • Generally removing unwanted emails on an organization-wide scale