urn:noticeable:projects:EwfvoE1WpdtwVJYBfmCzBarracuda Impersonation Protection Updatessentinel.barracudanetworks.com2023-09-27T16:09:25.168ZCopyright © Barracuda Impersonation ProtectionNoticeable#1e88e5urn:noticeable:publications:e760Rg4fPnBJh488fAk72023-09-27T16:08:17.852Z2023-09-27T16:09:25.168ZImpersonation Protection Classifier EnhancementsIncreased Impersonation Protection efficacy by improving detections and reducing false positives. Enhancements have been made in the following areas:
QR code-based attacks
Scam related campaigns
Business email compromise
Admin users...<p>Increased Impersonation Protection efficacy by improving detections and reducing false positives. Enhancements have been made in the following areas:</p><ul><li><p>QR code-based attacks</p></li><li><p>Scam related campaigns</p></li><li><p>Business email compromise</p></li></ul><p>Admin users will see these detections on the Impersonation Protection UI. We encourage all users to submit missed emails and incorrect detections via the <a href="https://campus.barracuda.com/doc/98224821/?utm_source=noticeable&utm_campaign=ewfvoe1wpdtwvjybfmcz.impersonation-protection-classifier-enhancements&utm_content=publication+link&utm_id=EwfvoE1WpdtwVJYBfmCz.JZydzOwCFULC2ba2kCev.e760Rg4fPnBJh488fAk7&utm_medium=newspage" target="_self"><span style="text-decoration: underline">Barracuda Email Protection Add-In</span></a>.</p>Barracuda Networksdhara@barracuda.comurn:noticeable:publications:bLls17UfeYCWDvz9KFki2023-04-20T21:40:23.248Z2023-04-20T21:42:24.394ZHighlighting Keywords, Statistics and MoreIn the analysis panel for a message, in addition to Severity, Confidence, Determination and Key Indicators, we now have Highlighting of Keywords in the body, Headers and Statistics.
To Enable Highlighting:
From within a message, toggle to...<p>In the analysis panel for a message, in addition to Severity, Confidence, Determination and Key Indicators, we now have Highlighting of Keywords in the body, Headers and Statistics.</p><p>To Enable Highlighting:<br>From within a message, toggle to enable Highlighting at top-right to see the elements of a message that Barracuda Impersonation Protection deem as suspicious. Keywords and phrases in the message content will have red boxes around them. Other identifiers, shown via the Sender Information chips and Header information will display in red. The Email and Header tabs will show red dots if they display suspicious information.</p><p></p><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/bLls17UfeYCWDvz9KFki/01h55ta3gsy08xs1km6pn4qhg4-image.png" alt="" loading="lazy" title=""></figure><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/bLls17UfeYCWDvz9KFki/01h55ta3gswqn0gjdgp60xvkpt-image.png" alt="" loading="lazy" title=""></figure><p></p><p>Learn more on <a href="https://campus.barracuda.com/product/sentinel/doc/91984521/spear-phishing-protection/?sl=AYegYsYNyCv54wKNpc2m&so=1&utm_source=noticeable&utm_campaign=ewfvoe1wpdtwvjybfmcz.highlighting-keywords-statistics-and-more&utm_content=publication+link&utm_id=EwfvoE1WpdtwVJYBfmCz.JZydzOwCFULC2ba2kCev.bLls17UfeYCWDvz9KFki&utm_medium=newspage#_7149c705" rel="noopener nofollow" target="_blank">campus</a></p>Barracuda Networksdhara@barracuda.comurn:noticeable:publications:p5v3OvqBsWw9LhdBMnO62022-11-01T22:28:06.744Z2022-11-01T22:31:32.783ZFalse Positive percentage in overview sectionYou can now see the FP% along with the total emails processed, and total threats detected in the overview section of Impersonation Protection. False positives is the percentage of messages marked as threats that were actually good emails....<p>You can now see the FP% along with the total emails processed, and total threats detected in the overview section of Impersonation Protection.</p><p><a href="https://campus.barracuda.com/product/sentinel/doc/80740499/false-positives?utm_source=noticeable&utm_campaign=ewfvoe1wpdtwvjybfmcz.false-positive-percentage-in-overview-section&utm_content=publication+link&utm_id=EwfvoE1WpdtwVJYBfmCz.JZydzOwCFULC2ba2kCev.p5v3OvqBsWw9LhdBMnO6&utm_medium=newspage" rel="noopener noreferrer" target="_blank">False positives</a> is the percentage of messages marked as threats that were actually good emails. An asterisks here means the percentage is less than 0.001%. You can hover over this number to see the actual percentage.</p><p></p><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/p5v3OvqBsWw9LhdBMnO6/01h55ta3gs0q3f4kwnsc341565-image.png" alt="" loading="lazy" title=""></figure><p></p><p>Campus: <a href="https://campus.barracuda.com/product/sentinel/article/preview/98212871?utm_source=noticeable&utm_campaign=ewfvoe1wpdtwvjybfmcz.false-positive-percentage-in-overview-section&utm_content=publication+link&utm_id=EwfvoE1WpdtwVJYBfmCz.JZydzOwCFULC2ba2kCev.p5v3OvqBsWw9LhdBMnO6&utm_medium=newspage" rel="noopener nofollow" target="_blank">https://campus.barracuda.com/product/sentinel/article/preview/98212871</a></p>Barracuda Networksdhara@barracuda.comurn:noticeable:publications:xahuYwU0Ia0W1vcOVvlx2022-07-28T15:28:35.828Z2022-07-28T22:35:56.199ZEnhancements and UI updatesClassifier Enhancements: Over the last couple of months, we have worked to improve our efficacy by improving detections and reducing false positives. Here are a few examples: Introduced a new classifier that identifies emails containing bad...<p><strong>Classifier Enhancements:</strong></p><p>Over the last couple of months, we have worked to improve our efficacy by improving detections and reducing false positives. Here are a few examples: </p><ul><li><p>Introduced a new classifier that identifies emails containing bad URLs from services utilizing IPFS links, which increased phishing detections.</p></li><li><p>HTML has now replaced PDF as the most weaponized artifact. We have added improvements to HTML attachment classifier as well as HTML classifier to further improve phishing detections.</p></li><li><p>ATO classifier enhancements to include <em>impossible travel</em> and other features to improve ATO detections and reduce false positives.</p></li><li><p>While most of our classifiers are language independent, there are some classifiers that perform better when trained in different languages. Our CEO Fraud classifier is one such classifier which has been enhanced through native Spanish, German, Italian, French, Portuguese, and Dutch support. In addition, Simple CEO classifier and BAIT (reconnaissance) classifiers have also been added to improve BEC detections.</p></li><li><p>A new classifier has been added to detect fake invoices which are embedded in emails.</p></li><li><p>Phish masking is a common technique used by attackers to hide malicious URLs behind link forwarding or shortening services. Many attackers use multiple forwarders (bit.ly, goo.gl or tiny URL for example) to evade detection. For example, a phishing_link.com maybe wrapped x number of times before the malicious link is finally opened. Attackers are also known to utilize well known services like Salesforce and SendGrid (just to name a couple) to mask their URLs. Ability to <strong>dynamically resolve and expand URLs</strong> has been greatly enhanced.</p></li></ul><p><strong>UI Enhancements:</strong> </p><p>In addition to the improvements to our classifiers we are pleased to announce that our migration efforts to the new, more engaging technology is now complete. This allows us to quickly build and iterate on new features that you have asked for. One such feature is the addition of the “Statistics Tab”. To help you better understand why an email was blocked, we now have Sender Analysis and Sender Authentication details in addition to Confidence & Severity level, and Key Indicators when you click on more details to review an alert. </p><p></p><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/xahuYwU0Ia0W1vcOVvlx/01h55ta3gsjjfms9d8p1zt6wb9-image.png" alt="" loading="lazy" title=""></figure><p></p>Barracuda Networksdhara@barracuda.comurn:noticeable:publications:DmORlsdrZCnbSubffnmv2021-12-06T17:26:08.790Z2021-12-06T18:09:27.767ZYour UI has a new look!We are currently in Beta. To get added to our beta program, please send us an email at emailproductfeedback@barracuda.com. As part of our efforts to faster development and moving to newer technology, your UI now has a new look when you log...<p>We are currently in Beta. To get added to our beta program, please send us an email at emailproductfeedback@barracuda.com. </p><p>As part of our efforts to faster development and moving to newer technology, your UI now has a new look when you log into Impersonation Protection. Here is the new look:</p><p></p><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/DmORlsdrZCnbSubffnmv/01h55ta3gsbs2h9r54srz3rwdj-image.jpg" alt="" loading="lazy" title=""></figure><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/DmORlsdrZCnbSubffnmv/01h55ta3gsh55r37apqxy9jsa4-image.jpg" alt="" loading="lazy" title=""></figure><p></p><p><strong>Benefits to you</strong> </p><ul><li><p>Our users are always at the heart of our innovations and this release gives us greater flexibility and increased speed in integrating the new features you have been requesting</p></li><li><p>You now have visibility into the confidence score each email gets when processed via Impersonation Protection</p></li><li><p>You can also see the severity of a threat against each email</p></li><li><p>You have the ability to set up different email addresses for ATO alerts vs Phishing alerts.</p></li></ul>Barracuda Networksdhara@barracuda.comurn:noticeable:publications:fadCmv9Au6FzteFUD5p22021-12-06T16:23:08.126Z2021-12-06T16:23:51.563ZNEW! Email Protection SaaS PlansThey’re here! We are excited to announce the general availability of our new email protection plans. As part of our mission to provide innovative security products that are easy to buy, deploy, and use, our new plans are designed to better...<p>They’re here! We are excited to announce the general availability of our new email protection plans. As part of our mission to provide innovative security products that are easy to buy, deploy, and use, our new plans are designed to better align with customer’s Office 365 security needs and buying preferences. As an existing customer there will be <strong>no changes to your products or plans</strong>. However, some features have new, more descriptive names and have undergone small changes. For more information on the new plans please visit <a href="https://campus.barracuda.com/doc/96014231/?utm_source=noticeable&utm_campaign=ewfvoe1wpdtwvjybfmcz.new-email-protection-saas-plans&utm_content=publication+link&utm_id=EwfvoE1WpdtwVJYBfmCz.JZydzOwCFULC2ba2kCev.fadCmv9Au6FzteFUD5p2&utm_medium=newspage" rel="noopener nofollow" target="_blank">https://campus.barracuda.com/doc/96014231/</a></p><p> </p>Barracuda Networksdhara@barracuda.comurn:noticeable:publications:0BAKGcLvbp2E2B2hP10N2021-07-07T21:35:24.156Z2021-07-07T21:41:01.251ZSchedule Sentinel ReportBarracuda Sentinel automatically emails reports to you or your team on a regular basis, so you can keep up with recent activity. By default, Barracuda Sentinel emails monthly reports to the security team email specified on the Remediation...<p>Barracuda Sentinel automatically emails reports to you or your team on a regular basis, so you can keep up with recent activity. By default, Barracuda Sentinel emails monthly reports to the security team email specified on the <strong>Remediation</strong> tab in the Settings. </p><p>To schedule email reports:</p><ol><li><p>Open Barracuda Sentinel. </p></li><li><p>Click the Settings icon to access the administrative functions. </p></li><li><p>Select the <strong>Reports</strong> tab.</p></li><li><p>By default, <strong>Send reports by email</strong> is set to <strong>On</strong> (blue).</p></li><li><p>Select the time range for the data you want to see in the reports. Options are <strong>Last 7 Days</strong>, <strong>Last 30 Days</strong>, or <strong>Last 90 Days</strong>. The default value is <strong>Last 30 Days</strong>. </p></li><li><p>Specify the report recipient. By default, emails are sent to the security team email specified on the <strong>Remediation</strong> tab. <br>To specify a different recipient, switch the toggle to <strong>Off</strong> (grey) and type one email address in the <strong>Send to</strong> field that appears. </p></li><li><p>In the <strong>Start date</strong> field, type or select the date you want to start receiving automated emails. </p></li><li><p>In the <strong>Frequency</strong> field, specify how often you want to receive reports. Options are <strong>Daily</strong>, <strong>Weekly</strong>, and <strong>Monthly</strong>. The default value is <strong>Monthly</strong>. </p></li><li><p>Click <strong>Save</strong>. </p></li></ol><p><strong>Discontinuing Email Reports</strong></p><p>If you do not want to receive these automated emails, you can stop them by changing the settings to toggle <strong>off</strong> for <strong>Send reports by email</strong></p><p>In the future we plan to support other formats. However, for now an email will be sent with the data requested. </p>Barracuda Networksdhara@barracuda.comurn:noticeable:publications:5a8PznH77bNtxm5OPaqq2021-04-23T19:45:26.397Z2021-04-23T19:58:58.492ZFeedback on Reported MessagesWe heard your feedback. When you report a message as False Positive in Barracuda Sentinel, in addition to the submission confirmation, as the first step, you will also be asked to provide additional details as to why you think that message...<p>We heard your feedback. When you report a message as False Positive in Barracuda Sentinel, in addition to the submission confirmation, as the first step, you will also be asked to provide additional details as to why you think that message was false positive. In the future, we will provide the steps we took based on this additional information.<br>If you choose to provide these details, you will be redirected to a feedback response form to select a reason from a list of options or to type in a reason. </p><p></p><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/5a8PznH77bNtxm5OPaqq/01h55ta3gsy9h0cr2efz63vjh1-image.jpg" alt="" loading="lazy" title=""></figure><p></p><p></p><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/5a8PznH77bNtxm5OPaqq/01h55ta3gsb4gc7embjy5s11tr-image.jpg" alt="" loading="lazy" title=""></figure><p></p><p></p><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/5a8PznH77bNtxm5OPaqq/01h55ta3gsth1st5qs0kw8kfdz-image.jpg" alt="" loading="lazy" title=""></figure><p></p><p></p><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/5a8PznH77bNtxm5OPaqq/01h55ta3gsz0krw109fcg1qv1x-image.jpg" alt="" loading="lazy" title=""></figure>You can also click on the link "Report this is not phishing" from within the alert email you receive for an attack. This will follow the same workflow once you click on the link, where the form for additional feedback is presented. <p></p><p></p><figure><img src="https://storage.noticeable.io/projects/EwfvoE1WpdtwVJYBfmCz/publications/5a8PznH77bNtxm5OPaqq/01h55ta3gsysr558j48gexh6k8-image.jpg" alt="" loading="lazy" title=""></figure><p></p><p>You can also find this information on campus here: <a href="https://campus.barracuda.com/product/sentinel/doc/80740499/false-positives/?utm_source=noticeable&utm_campaign=ewfvoe1wpdtwvjybfmcz.feedback-on-reported-messages&utm_content=publication+link&utm_id=EwfvoE1WpdtwVJYBfmCz.JZydzOwCFULC2ba2kCev.5a8PznH77bNtxm5OPaqq&utm_medium=newspage" rel="noopener nofollow" target="_blank">https://campus.barracuda.com/product/sentinel/doc/80740499/false-positives/</a></p>Barracuda Networksdhara@barracuda.comurn:noticeable:publications:AJPv1ViuGB1bBQsk40YY2020-03-23T18:42:00.001Z2020-03-23T18:44:40.073ZChanged "Quarantined" to "Moved to Junk folder" The action to move a malicious email to a user's Junk folder was previously labeled as "Quarantined". This was confusing to many customers because the Barracuda Email Security Service also uses the same term. This action is now referred...<p>The action to move a malicious email to a user’s Junk folder was previously labeled as "Quarantined". This was confusing to many customers because the Barracuda Email Security Service also uses the same term. This action is now referred to as “Moved to Junk folder” to reduce confusion. There is no change in behavior.</p>
Barracuda Networksaseem@aseem.usurn:noticeable:publications:qE4CkLh2uMOA3hhwcK8S2020-03-20T18:20:00.001Z2020-03-23T18:49:23.037ZNew usage reportWe just released a report showing which Office 365 mailboxes are licensed and monitored. You can view the report by going to the dashboard page on Barracuda Sentinel. It displays a list of all the mailboxes (users and shared mailboxes...<p>We just released a report showing which Office 365 mailboxes are licensed and monitored.</p>
<p>You can view the report by going to the dashboard page on Barracuda Sentinel. It displays a list of all the mailboxes (users and shared mailboxes) and whether they have an Exchange license entitelment or not, and whether it is being monitored and protected by Barracuda Sentinel or not.</p>
<p>It is possible that a mailbox does not have an Exchange license, but Barracuda Sentinel will still monitor and protect it. There is also the case where a mailbox is licensed but we are unable to monitor it. Those are rare.</p>
<p>We think the report will go a long way in helping you understand which mailboxes are being protected by Barracuda Sentinel.</p>
<p>Learn more about it at <a href="https://campus.barracuda.com/product/sentinel/doc/91984521/understanding-the-dashboard/?utm_source=noticeable&utm_campaign=ewfvoe1wpdtwvjybfmcz.new-usage-report&utm_content=publication+link&utm_id=EwfvoE1WpdtwVJYBfmCz.JZydzOwCFULC2ba2kCev.qE4CkLh2uMOA3hhwcK8S&utm_medium=newspage" target="_blank" rel="noopener">https://campus.barracuda.com/product/sentinel/doc/91984521/understanding-the-dashboard/</a></p>
Barracuda Networksaseem@aseem.us