Skip to content

Security

The Security module bundles browser vulnerability exposure, real-time anti-spoofing, file-type download filtering, and an on-demand file sandbox. It requires an active subscription.

Vulnerability Exposure

Automatic scanning of browser installations across your fleet against a curated CVE database.

  • Vulnerabilities are matched by browser name and version.
  • Each vulnerability carries a CVE ID, severity, and CVSS score.
  • Vulnerabilities are automatically resolved once the affected browser has been updated on the user's device.
  • Results appear on the Vulnerability Dashboard (Security → Vulnerabilities).

The dashboard shows total vulnerabilities, count of critical/high issues, affected-browsers count, breakdown by severity, timeline of discoveries, and a detailed activity table.

Anti-Spoofing

Real-time detection of look-alike and credential-harvesting sites. The browser extension checks each visited URL against spoofing indicators; the Outlook add-in inspects email HTML for the same signals.

Configured per policy on the Security tab with one of four modes:

  • Disabled — no spoofing detection.
  • Report Only — silently log alerts; the user is not notified.
  • Warn & Overridable — warn the user; they can dismiss and proceed.
  • Block if Certain — block high-confidence detections; warn on lower-confidence ones.

The Spoofing Dashboard (Security → Spoofing) shows total alerts, blocked attempts, dismissed warnings, breakdown by alert type, timeline, and a detailed activity table.

Download Guard / Attachment Guard

File-type filtering for downloads (Browser Extension) and email attachments (Outlook Add-in). Filters are attached to policies and enforced on matching pages / matching outbound emails.

Filter modes

  • Blocklist — listed extensions are blocked; all others are allowed.
  • Whitelist — only listed extensions are allowed; all others are blocked.

Enforcement modes

  • Report — log silently; no user-visible action.
  • Alert — warn the user; the download or send is allowed.
  • Warn & Overridable — warn the user; the download or send is blocked until the user overrides.
  • Block — block the download or send; no override.

Predefined templates

Four templates are available when creating a new download filter:

  • Executables — blocks .exe, .bat, .cmd, .msi, .ps1, etc. (block mode)
  • Archives — warns on .zip, .rar, .7z, .tar, etc. (warn mode)
  • Documents Only — whitelist of .pdf, .docx, .xlsx, .pptx, etc.
  • High Risk — blocks .scr, .vbs, .js, .wsf, etc.

Audit trail

Every download and every attachment is tracked (file name, extension, size) regardless of whether a download filter is active. The Download Guard dashboard is the complete audit trail across your organization.

File Sandbox

On-demand file analysis for administrators. Upload any single file (up to 25 MB) to have it detonated in an isolated sandbox.

  • The File Sandbox tab (Security → File Sandbox) lists every submission with time, filename, submitter, verdict, and quick access to details.
  • Use New submission to open a dialog for a single file plus optional context notes.
  • The submission's detail page shows the verdict, indicators of compromise, MITRE ATT&CK techniques, per-file heuristics, and an AI-generated summary. The same view is used on Phishing Triage.
  • The uploaded file is deleted automatically once analysis completes; only the verdict, IOCs, and AI summary remain on the submission.
  • The admin who submitted a file receives an email with the verdict, risk score, and AI summary once analysis is done.

Alerts

Security events generate alerts visible in the Alerts section. Types include vulnerability detections, phishing/spoofing indications and blocks, download warnings and blocks, browser-native warning forwarding (Safe Browsing / SmartScreen, certificate errors), and sandbox submissions.