← All cheat sheets

IRONPORT_ESA

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Cisco IronPort ESA (Email Security Appliance) handles inbound/outbound mail filtering.
Essential for SOC operations, DLP verification, and phishing investigation.
Primary log source: mail_logs (message tracking) + CLI tools.

LOG LOCATIONS#

/data/log/mail/mail_logs            # Main mail transaction log
/data/log/mail/system_logs          # System events
/data/log/mail/error_logs           # Error events
/data/log/asarchive/                # Anti-spam archive
/data/log/avarchive/                # Anti-virus archive
/data/log/amp/                      # AMP (File Reputation) logs
/data/log/cli_logs/                 # CLI audit trail
/data/log/gui_logs/                 # GUI audit trail
/data/log/authentication/           # Auth events
/data/log/ldap_logs/                # LDAP queries
/data/log/reportd_logs/             # Reporting daemon
/data/log/trackerd_logs/            # Message tracking
/data/log/euq_logs/                 # End User Quarantine

CLI BASIC USAGE#

grep                                # Search logs via CLI
tail                                # Tail active log
less                                # Paginate log
findevent                           # Find event by MID/ICID/DCID
mailconfig                          # Mail config dump
displayalerts                       # Recent system alerts
status                              # System status
version                             # Appliance version
hoststatus example.com              # Destination host status
tophosts                            # Top destination hosts
topin                               # Top incoming senders
rate                                # Real-time rate monitor

MESSAGE TRACKING IDS#

MID     Message ID         Unique per message
ICID    Injection Conn ID  Inbound SMTP connection
DCID    Delivery Conn ID   Outbound SMTP connection
RID     Recipient ID       Per-recipient within MID
RCID    Reporting Conn ID  Reporting correlation

# One MID can have multiple RIDs (one per recipient)
# One ICID can carry multiple MIDs

GREP IN LOGS (CLI)#

grep "MID 123456" mail_logs              # Track specific message
grep "ICID 789012" mail_logs             # Track injection connection
grep "DCID 345678" mail_logs             # Track delivery connection
grep -i "user@example.com" mail_logs     # Search by address
grep "Subject:" mail_logs                # All subjects
grep "attachment" mail_logs              # Attachments
grep -c "BLOCKED" mail_logs              # Count blocks
grep -E "ICID [0-9]+ ACCEPT" mail_logs   # Accepted injections

FINDEVENT (CLI Tool)#

findevent                                # Interactive prompt
# Options:
#  1. Search by envelope sender
#  2. Search by envelope recipient
#  3. Search by message subject
#  4. Search by other criteria (MID, ICID, DCID)
#  5. Display by hour

# Non-interactive usage:
grep "MID 123456" mail_logs | less

MESSAGE TRACKING (GUI / API)#

# GUI: Monitor > Message Tracking
# Search criteria:
Envelope Sender                     # MAIL FROM
Envelope Recipient                  # RCPT TO
Subject                             # Header Subject
Message ID Header                   # RFC 822 Message-ID
Cisco IronPort MID                  # Internal MID
Attachment Name                     # File name
Attachment SHA256                   # File hash
SDR Verdict                         # Sender Domain Reputation
URL Reputation                      # URL category/reputation
Message Event                       # Final action

DETECTING BLOCKED MESSAGES#

# Anti-Spam (CASE / IPAS) blocks
grep "Positive" mail_logs | grep "MID"
grep "ANTISPAM:" mail_logs
# Example line:
# MID 12345 interim verdict using engine: CASE spam positive
# MID 12345 using engine: CASE spam positive

# Anti-Virus (Sophos/McAfee) blocks
grep "ANTIVIRUS:" mail_logs
grep "Sophos" mail_logs | grep -i "virus"
# Example:
# MID 12345 antivirus positive 'EICAR-AV-Test'
# MID 12345 Dropped by antivirus

# AMP (File Reputation / Analysis)
grep "AMP" mail_logs
grep "File reputation" mail_logs
grep "Malicious" mail_logs | grep "AMP"
# Verdicts: CLEAN / MALICIOUS / UNKNOWN / UNSCANNABLE / LOW RISK
# Example:
# MID 12345 AMP file reputation verdict: MALICIOUS
# MID 12345 File 'invoice.pdf' SHA256 abc... verdict MALICIOUS

# Content Filter blocks
grep "CF matched" mail_logs
grep "content filter" mail_logs
# Example:
# MID 12345 matched Content Filter 'Block_Executables'
# MID 12345 quarantined to 'Policy' by CF 'Strip_EXE'

# Message Filter blocks
grep "MF matched" mail_logs
grep "^.*MID [0-9]+ matched filter" mail_logs

# Outbreak Filter
grep "Outbreak" mail_logs
# MID 12345 Outbreak Filters: quarantined (Virus)
# MID 12345 Threat Level=5 Category=Phish

# DLP (Data Loss Prevention)
grep "DLP" mail_logs
grep "DLP violation" mail_logs
# MID 12345 DLP violation 'PCI-DSS' severity CRITICAL

# Graymail / Marketing
grep "Graymail" mail_logs
# MID 12345 Graymail: Marketing

# URL Filtering (WBRS / Talos)
grep "URL" mail_logs | grep -i "malicious\|suspect"
# MID 12345 URL 'http://bad.com' reputation MALICIOUS

# SPF/DKIM/DMARC failures
grep "SPF" mail_logs | grep -i "fail\|softfail"
grep "DKIM" mail_logs | grep -i "fail"
grep "DMARC" mail_logs | grep -i "fail\|reject\|quarantine"
# ICID 789 SPF: helo identity fail
# MID 12345 DKIM: verification failed
# MID 12345 DMARC: verification failed, action: reject

FINAL ACTIONS (WHAT HAPPENED)#

# In mail_logs, look for the FINAL verdict:
queued for delivery                 # Accepted, queued
Delivered                           # Successfully delivered
to RID                              # Delivery success per recipient
Bounced                             # Hard bounce
Soft bounced                        # Temp failure
DSN                                 # Delivery Status Notification
quarantined to                      # Quarantined (Policy/Virus/Outbreak/Spam)
Dropped                             # Silently dropped
Rejected                            # 5xx rejection at SMTP
TCPREFUSE                           # Connection refused (SBRS/HAT)
Deferred                            # Temp defer
rewritten                           # URL/attachment rewritten

# Examples:
grep "MID 12345" mail_logs | grep -E "quarantined|Dropped|Rejected|Bounced|Delivered"

REASONS FOR BLOCK / DELIVERY#

# For a given MID, the "story" is:
# 1. ICID ACCEPT/REJECT (HAT/SBRS decision)
# 2. MID created, MAIL FROM / RCPT TO
# 3. Engine verdicts: ANTISPAM, ANTIVIRUS, AMP, Outbreak, DLP, URL
# 4. Content/Message Filter matches
# 5. Final: queued / quarantined / dropped / bounced / delivered

# Reconstruct the full story:
grep -E "ICID 789|MID 12345" mail_logs

# Just the verdicts:
grep "MID 12345" mail_logs | grep -E "verdict|matched|quarantined|Dropped|positive|Delivered"

HAT / SBRS (Sender Reputation)#

# Host Access Table decisions at ICID level
grep "ICID 789" mail_logs
# ICID 789 ACCEPT SG SUSPECTLIST match sbrs[-3.0:-1.0] SBRS -2.5
# ICID 789 REJECT SG BLACKLIST match sbrs[-10.0:-3.0] SBRS -5.0
# ICID 789 TCPREFUSE   # Rejected before data
# SBRS scale: -10 (bad) to +10 (good), None = no data

# Sender Groups:
BLACKLIST / BLOCKED                 # Rejected
SUSPECTLIST                         # Throttled
UNKNOWNLIST                         # Default
WHITELIST / ALLOWED                 # Trusted
RELAYLIST                           # Internal relay

QUARANTINES#

# Default/built-in quarantines:
Policy                              # Content filter holds
Virus                               # AV positive
Outbreak                            # Outbreak Filters
File Analysis                       # AMP sandboxing
Unscannable                         # Could not scan
Spam / EUQ                          # End-User Quarantine

# CLI quarantine operations:
quarantineconfig                    # Configure
# GUI: Monitor > Policy, Virus, and Outbreak Quarantines

ATTACHMENT / FILE INVESTIGATION#

# Find attachment by name
grep -i "invoice.pdf" mail_logs
grep "Attachment" mail_logs

# Find by SHA256 (AMP)
grep "abc123def456" amp/current

# AMP verdict history
grep "SHA256" amp/current | grep "MALICIOUS"

# File analysis (sandbox) pending/complete
grep "File Analysis" mail_logs
# MID 12345 File 'sample.docx' sent for analysis
# MID 12345 File Analysis verdict: MALICIOUS

URL / PHISHING INVESTIGATION#

# URL reputation decisions
grep -E "URL.*reputation|URL.*category" mail_logs
grep "rewritten" mail_logs          # URL defense rewrites

# Find messages with specific URL
grep "http://suspicious.com" mail_logs

# Phishing / Outbreak
grep "Category=Phish" mail_logs
grep "Threat Level" mail_logs

SEARCHING BY COMMON CRITERIA#

# By sender
grep -i "from=<attacker@evil.com>" mail_logs
grep -i "MAIL FROM" mail_logs | grep "evil.com"

# By recipient
grep -i "to=<victim@corp.lu>" mail_logs
grep -i "RCPT TO" mail_logs | grep "corp.lu"

# By subject
grep -i "Subject:.*invoice" mail_logs

# By IP
grep "10.0.0.5" mail_logs
grep "ICID.*10.0.0.5" mail_logs

# By time (last hour) - tail + timestamps
tail -n 10000 mail_logs | grep "$(date '+%a %b %d %H')"

LOG LINE ANATOMY#

# Typical mail_logs entries:

# Connection accepted
Mon Apr 14 10:23:45 2026 Info: New SMTP ICID 789012 interface
  Management (10.0.0.10) address 203.0.113.5 reverse dns host
  mail.sender.com verified yes

# HAT decision
Mon Apr 14 10:23:45 2026 Info: ICID 789012 ACCEPT SG UNKNOWNLIST
  match sbrs[-1.0:10.0] SBRS 2.1

# Message injected
Mon Apr 14 10:23:46 2026 Info: Start MID 123456 ICID 789012

# Envelope
Mon Apr 14 10:23:46 2026 Info: MID 123456 ICID 789012 From:
  <sender@example.com>
Mon Apr 14 10:23:46 2026 Info: MID 123456 ICID 789012 RID 0 To:
  <user@corp.lu>

# Subject
Mon Apr 14 10:23:46 2026 Info: MID 123456 Subject 'Your invoice'

# Verdicts
Mon Apr 14 10:23:47 2026 Info: MID 123456 interim verdict using
  engine: CASE spam negative
Mon Apr 14 10:23:47 2026 Info: MID 123456 antivirus negative
Mon Apr 14 10:23:48 2026 Info: MID 123456 AMP file reputation verdict
  : CLEAN

# Final action
Mon Apr 14 10:23:48 2026 Info: MID 123456 queued for delivery
Mon Apr 14 10:23:49 2026 Info: Delivery start DCID 345678 MID 123456
  to RID [0]
Mon Apr 14 10:23:49 2026 Info: Message done DCID 345678 MID 123456 to
  RID [0]

COMMON BLOCK SIGNATURES#

# Spam blocked
"CASE spam positive"
"interim verdict using engine: CASE spam positive"

# Virus blocked
"antivirus positive"
"Dropped by antivirus"

# AMP malicious
"AMP file reputation verdict: MALICIOUS"
"File Analysis verdict: MALICIOUS"

# Outbreak blocked
"Outbreak Filters: quarantined"
"Threat Level=5"

# Content filter drop
"CF matched"
"dropped by filter"

# DLP block
"DLP violation"
"Action: QUARANTINE"

# DMARC reject
"DMARC: verification failed, action: reject"

# Connection rejected
"ICID .* REJECT"
"TCPREFUSE"

QRADAR AQL QUERIES#

# Requires DSM: Cisco IronPort ESA / Cisco ESA
# Typical LogSource Type: "Cisco IronPort"

# All blocked emails last 24h
SELECT QIDNAME(qid), sourceip, destinationip, "Sender", "Recipient",
       "Subject", "Verdict", "Action"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND "Action" ILIKE '%block%' OR "Action" ILIKE '%drop%'
  OR "Action" ILIKE '%quarantine%' OR "Action" ILIKE '%reject%'
LAST 24 HOURS

# Messages with AMP MALICIOUS verdict
SELECT devicetime, "Sender", "Recipient", "Subject",
       "Attachment Name", "SHA256", "Verdict"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND "Verdict" ILIKE '%MALICIOUS%'
LAST 7 DAYS

# Anti-spam positives
SELECT devicetime, sourceip, "Sender", "Recipient", "Subject",
       "Spam Verdict"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND "Spam Verdict" ILIKE '%positive%'
LAST 24 HOURS

# DMARC failures
SELECT devicetime, "Sender", "Recipient", "Subject", "DMARC Result"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND "DMARC Result" ILIKE '%fail%'
LAST 24 HOURS

# Top senders of blocked mail
SELECT "Sender", COUNT(*) as cnt
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND ("Action" ILIKE '%block%' OR "Verdict" ILIKE '%MALICIOUS%')
GROUP BY "Sender"
ORDER BY cnt DESC
LAST 7 DAYS

# Top targeted recipients
SELECT "Recipient", COUNT(*) as cnt
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND "Verdict" ILIKE '%MALICIOUS%'
GROUP BY "Recipient"
ORDER BY cnt DESC
LAST 30 DAYS

# Outbound DLP violations
SELECT devicetime, "Sender", "Recipient", "DLP Policy", "Severity"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND "DLP Policy" IS NOT NULL
LAST 7 DAYS

# Connections rejected by HAT/SBRS
SELECT sourceip, COUNT(*) as rejects
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND "Action" ILIKE '%REJECT%'
GROUP BY sourceip
ORDER BY rejects DESC
LAST 24 HOURS

# Track specific MID
SELECT *
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND "MID" = '123456'
LAST 7 DAYS

# Messages with URL rewrites (URL defense triggered)
SELECT "Sender", "Recipient", "Subject", "URL"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND payload ILIKE '%rewritten%'
LAST 24 HOURS

# Outbreak Filter hits
SELECT devicetime, "Sender", "Recipient", "Subject",
       "Threat Level", "Threat Category"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
  AND "Threat Level" >= 3
LAST 24 HOURS

MICROSOFT DEFENDER XDR / SENTINEL (KQL)#

# For hybrid environments where ESA fronts Exchange Online
# Correlate ESA verdicts with Defender for Office 365

# EmailEvents - blocked/quarantined
EmailEvents
| where Timestamp > ago(24h)
| where DeliveryAction in ("Blocked", "Junked", "Replaced")
| project Timestamp, SenderFromAddress, RecipientEmailAddress,
          Subject, DeliveryAction, ThreatTypes, DetectionMethods

# Malicious attachments
EmailAttachmentInfo
| where Timestamp > ago(7d)
| where ThreatTypes has "Malware"
| project Timestamp, FileName, SHA256, ThreatTypes, FileType
| join kind=inner EmailEvents on NetworkMessageId
| project Timestamp, SenderFromAddress, RecipientEmailAddress,
          Subject, FileName, SHA256, ThreatTypes

# URL clicks on malicious links
UrlClickEvents
| where Timestamp > ago(7d)
| where ThreatTypes != ""
| project Timestamp, AccountUpn, Url, ThreatTypes, ActionType,
          IsClickedThrough

# Users who clicked through warnings
UrlClickEvents
| where Timestamp > ago(30d)
| where IsClickedThrough == true
| where ThreatTypes contains "Phish" or ThreatTypes contains "Malware"
| summarize Clicks=count(), Urls=make_set(Url) by AccountUpn

# Phishing delivered to inbox
EmailEvents
| where Timestamp > ago(24h)
| where ThreatTypes has "Phish"
| where DeliveryLocation == "Inbox"
| project Timestamp, SenderFromAddress, RecipientEmailAddress,
          Subject, ThreatTypes, DeliveryAction

# Correlate email with endpoint detonation
EmailAttachmentInfo
| where Timestamp > ago(7d)
| where ThreatTypes has "Malware"
| join kind=inner (
    DeviceFileEvents
    | where Timestamp > ago(7d)
) on SHA256
| project Timestamp, RecipientEmailAddress, DeviceName,
          FileName, SHA256, ActionType

# Emails from specific sender domain
EmailEvents
| where Timestamp > ago(7d)
| where SenderFromDomain == "suspicious-domain.com"
| project Timestamp, SenderFromAddress, RecipientEmailAddress,
          Subject, DeliveryAction, ThreatTypes

# DMARC/DKIM/SPF failures
EmailEvents
| where Timestamp > ago(24h)
| where AuthenticationDetails has_any ("fail", "softfail")
| project Timestamp, SenderFromAddress, RecipientEmailAddress,
          Subject, AuthenticationDetails, DeliveryAction

# Top phishing targets
EmailEvents
| where Timestamp > ago(30d)
| where ThreatTypes has "Phish"
| summarize Attempts=count() by RecipientEmailAddress
| order by Attempts desc
| take 20

# ZAP (Zero-hour Auto Purge) events
EmailPostDeliveryEvents
| where Timestamp > ago(7d)
| where Action == "ZAP"
| project Timestamp, RecipientEmailAddress, Subject, ThreatTypes,
          Action, ActionResult

# Correlate ESA block with Defender (same SHA256)
// Run in Defender after identifying SHA256 from ESA logs
let esa_sha = "abc123def456...";
union EmailAttachmentInfo, DeviceFileEvents
| where SHA256 == esa_sha
| project Timestamp, Type=case(
    $table == "EmailAttachmentInfo", "Email",
    $table == "DeviceFileEvents", "Endpoint",
    "Unknown"),
    FileName, DeviceName=coalesce(DeviceName,""),
    Recipient=coalesce(RecipientEmailAddress,"")

# Impersonation attempts (display-name spoof)
EmailEvents
| where Timestamp > ago(7d)
| where ThreatTypes has_any ("Impersonation", "Spoof")
| project Timestamp, SenderDisplayName, SenderFromAddress,
          RecipientEmailAddress, Subject, ThreatTypes

INVESTIGATION WORKFLOWS#


    

WORKFLOW 1: User reports phishing#

1. Get: sender, subject, timestamp, recipient
2. ESA Message Tracking -> find MID
3. CLI: grep "MID xxxxx" mail_logs
4. Check verdicts: SPF/DKIM/DMARC, Spam, AV, AMP, Outbreak, URL
5. Get SHA256 of attachments, URLs
6. Pivot to Defender: EmailAttachmentInfo / UrlClickEvents by SHA256/URL
7. Check other recipients: same sender / subject / SHA256
8. Check endpoint execution: DeviceFileEvents / DeviceProcessEvents
9. If delivered: trigger remediation (Purge + ZAP)
10. Block: sender domain, URL, file hash at ESA + Defender

WORKFLOW 2: DLP outbound investigation#

1. ESA Message Tracking -> DLP policy hits
2. grep "DLP violation" mail_logs
3. Identify: policy, severity, sender, recipient, data type
4. Review message content in quarantine (if severity allows)
5. Interview user / verify business justification
6. QRadar: correlate with user activity (badge, VPN, file access)
7. Document in ticket; escalate if CRITICAL severity

WORKFLOW 3: Mass delivery failure#

1. CLI: hoststatus <destination>
2. tophosts to see destination queue
3. grep "Soft bounced\|Bounced" mail_logs | tail
4. Check: DNS, destination MTA status, our IP reputation
5. Check SBRS of our outbound IP (talosintelligence.com)
6. Check DMARC/SPF/DKIM on our sending domain

WORKFLOW 4: Suspected compromised internal sender#

1. grep "from=<user@corp.lu>" mail_logs | wc -l
2. Compare baseline volume
3. Check: unusual subjects, external recipients, bulk patterns
4. grep MID matching suspicious messages
5. Pivot Defender: AADSignInEventsBeta for the user
6. Check: impossible travel, new device, MFA anomalies
7. Trigger: password reset, session revoke, MFA re-enroll

QUICK REFERENCE#

grep "MID 12345" mail_logs                Track message
grep "ICID 789" mail_logs                 Track connection
grep "CASE spam positive" mail_logs       Spam blocks
grep "antivirus positive" mail_logs       AV blocks
grep "AMP.*MALICIOUS" mail_logs           AMP blocks
grep "Outbreak Filters" mail_logs         Outbreak blocks
grep "CF matched" mail_logs               Content filter
grep "DLP violation" mail_logs            DLP blocks
grep "DMARC.*fail" mail_logs              DMARC failures
grep "ICID.*REJECT" mail_logs             HAT rejections
grep "queued for delivery" mail_logs      Accepted
grep "quarantined to" mail_logs           Quarantined
grep "Dropped" mail_logs                  Silently dropped
findevent                                 Interactive search
tophosts                                  Destination queue
hoststatus <host>                         Host details
displayalerts                             Recent alerts
rate                                      Real-time rate

COMMON VERDICT STRINGS (BOOKMARK)#

CASE spam positive / negative / suspect
antivirus positive / negative / unscannable
AMP file reputation verdict: CLEAN / MALICIOUS / UNKNOWN / UNSCANNABLE
File Analysis verdict: MALICIOUS / CLEAN / PENDING
Outbreak Filters: quarantined / scheduled / scanned
CF matched / MF matched
DLP violation: <policy> severity CRITICAL / HIGH / MEDIUM / LOW
SPF: pass / fail / softfail / neutral / none
DKIM: pass / fail / none
DMARC: pass / fail action: none / quarantine / reject
SBRS: <score> or None
HAT: ACCEPT / REJECT / TCPREFUSE / RELAY

FINAL DISPOSITION KEYWORDS#

queued for delivery                       Accepted to queue
Delivered                                 Success
Bounced                                   Hard bounce (5xx)
Soft bounced                              Temp bounce (4xx)
quarantined to Policy                     Policy quarantine
quarantined to Virus                      Virus quarantine
quarantined to Outbreak                   Outbreak quarantine
quarantined to File Analysis              AMP sandbox
quarantined to Spam                       Spam quarantine
Dropped                                   Silent drop
Rejected                                  SMTP reject
TCPREFUSE                                 Connection refused