IRONPORT_ESA
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Cisco IronPort ESA (Email Security Appliance) handles inbound/outbound mail filtering. Essential for SOC operations, DLP verification, and phishing investigation. Primary log source: mail_logs (message tracking) + CLI tools.
LOG LOCATIONS#
/data/log/mail/mail_logs # Main mail transaction log /data/log/mail/system_logs # System events /data/log/mail/error_logs # Error events /data/log/asarchive/ # Anti-spam archive /data/log/avarchive/ # Anti-virus archive /data/log/amp/ # AMP (File Reputation) logs /data/log/cli_logs/ # CLI audit trail /data/log/gui_logs/ # GUI audit trail /data/log/authentication/ # Auth events /data/log/ldap_logs/ # LDAP queries /data/log/reportd_logs/ # Reporting daemon /data/log/trackerd_logs/ # Message tracking /data/log/euq_logs/ # End User Quarantine
CLI BASIC USAGE#
grep # Search logs via CLI tail # Tail active log less # Paginate log findevent # Find event by MID/ICID/DCID mailconfig # Mail config dump displayalerts # Recent system alerts status # System status version # Appliance version hoststatus example.com # Destination host status tophosts # Top destination hosts topin # Top incoming senders rate # Real-time rate monitor
MESSAGE TRACKING IDS#
MID Message ID Unique per message ICID Injection Conn ID Inbound SMTP connection DCID Delivery Conn ID Outbound SMTP connection RID Recipient ID Per-recipient within MID RCID Reporting Conn ID Reporting correlation # One MID can have multiple RIDs (one per recipient) # One ICID can carry multiple MIDs
GREP IN LOGS (CLI)#
grep "MID 123456" mail_logs # Track specific message grep "ICID 789012" mail_logs # Track injection connection grep "DCID 345678" mail_logs # Track delivery connection grep -i "user@example.com" mail_logs # Search by address grep "Subject:" mail_logs # All subjects grep "attachment" mail_logs # Attachments grep -c "BLOCKED" mail_logs # Count blocks grep -E "ICID [0-9]+ ACCEPT" mail_logs # Accepted injections
FINDEVENT (CLI Tool)#
findevent # Interactive prompt # Options: # 1. Search by envelope sender # 2. Search by envelope recipient # 3. Search by message subject # 4. Search by other criteria (MID, ICID, DCID) # 5. Display by hour # Non-interactive usage: grep "MID 123456" mail_logs | less
MESSAGE TRACKING (GUI / API)#
# GUI: Monitor > Message Tracking # Search criteria: Envelope Sender # MAIL FROM Envelope Recipient # RCPT TO Subject # Header Subject Message ID Header # RFC 822 Message-ID Cisco IronPort MID # Internal MID Attachment Name # File name Attachment SHA256 # File hash SDR Verdict # Sender Domain Reputation URL Reputation # URL category/reputation Message Event # Final action
DETECTING BLOCKED MESSAGES#
# Anti-Spam (CASE / IPAS) blocks grep "Positive" mail_logs | grep "MID" grep "ANTISPAM:" mail_logs # Example line: # MID 12345 interim verdict using engine: CASE spam positive # MID 12345 using engine: CASE spam positive # Anti-Virus (Sophos/McAfee) blocks grep "ANTIVIRUS:" mail_logs grep "Sophos" mail_logs | grep -i "virus" # Example: # MID 12345 antivirus positive 'EICAR-AV-Test' # MID 12345 Dropped by antivirus # AMP (File Reputation / Analysis) grep "AMP" mail_logs grep "File reputation" mail_logs grep "Malicious" mail_logs | grep "AMP" # Verdicts: CLEAN / MALICIOUS / UNKNOWN / UNSCANNABLE / LOW RISK # Example: # MID 12345 AMP file reputation verdict: MALICIOUS # MID 12345 File 'invoice.pdf' SHA256 abc... verdict MALICIOUS # Content Filter blocks grep "CF matched" mail_logs grep "content filter" mail_logs # Example: # MID 12345 matched Content Filter 'Block_Executables' # MID 12345 quarantined to 'Policy' by CF 'Strip_EXE' # Message Filter blocks grep "MF matched" mail_logs grep "^.*MID [0-9]+ matched filter" mail_logs # Outbreak Filter grep "Outbreak" mail_logs # MID 12345 Outbreak Filters: quarantined (Virus) # MID 12345 Threat Level=5 Category=Phish # DLP (Data Loss Prevention) grep "DLP" mail_logs grep "DLP violation" mail_logs # MID 12345 DLP violation 'PCI-DSS' severity CRITICAL # Graymail / Marketing grep "Graymail" mail_logs # MID 12345 Graymail: Marketing # URL Filtering (WBRS / Talos) grep "URL" mail_logs | grep -i "malicious\|suspect" # MID 12345 URL 'http://bad.com' reputation MALICIOUS # SPF/DKIM/DMARC failures grep "SPF" mail_logs | grep -i "fail\|softfail" grep "DKIM" mail_logs | grep -i "fail" grep "DMARC" mail_logs | grep -i "fail\|reject\|quarantine" # ICID 789 SPF: helo identity fail # MID 12345 DKIM: verification failed # MID 12345 DMARC: verification failed, action: reject
FINAL ACTIONS (WHAT HAPPENED)#
# In mail_logs, look for the FINAL verdict: queued for delivery # Accepted, queued Delivered # Successfully delivered to RID # Delivery success per recipient Bounced # Hard bounce Soft bounced # Temp failure DSN # Delivery Status Notification quarantined to # Quarantined (Policy/Virus/Outbreak/Spam) Dropped # Silently dropped Rejected # 5xx rejection at SMTP TCPREFUSE # Connection refused (SBRS/HAT) Deferred # Temp defer rewritten # URL/attachment rewritten # Examples: grep "MID 12345" mail_logs | grep -E "quarantined|Dropped|Rejected|Bounced|Delivered"
REASONS FOR BLOCK / DELIVERY#
# For a given MID, the "story" is: # 1. ICID ACCEPT/REJECT (HAT/SBRS decision) # 2. MID created, MAIL FROM / RCPT TO # 3. Engine verdicts: ANTISPAM, ANTIVIRUS, AMP, Outbreak, DLP, URL # 4. Content/Message Filter matches # 5. Final: queued / quarantined / dropped / bounced / delivered # Reconstruct the full story: grep -E "ICID 789|MID 12345" mail_logs # Just the verdicts: grep "MID 12345" mail_logs | grep -E "verdict|matched|quarantined|Dropped|positive|Delivered"
HAT / SBRS (Sender Reputation)#
# Host Access Table decisions at ICID level grep "ICID 789" mail_logs # ICID 789 ACCEPT SG SUSPECTLIST match sbrs[-3.0:-1.0] SBRS -2.5 # ICID 789 REJECT SG BLACKLIST match sbrs[-10.0:-3.0] SBRS -5.0 # ICID 789 TCPREFUSE # Rejected before data # SBRS scale: -10 (bad) to +10 (good), None = no data # Sender Groups: BLACKLIST / BLOCKED # Rejected SUSPECTLIST # Throttled UNKNOWNLIST # Default WHITELIST / ALLOWED # Trusted RELAYLIST # Internal relay
QUARANTINES#
# Default/built-in quarantines: Policy # Content filter holds Virus # AV positive Outbreak # Outbreak Filters File Analysis # AMP sandboxing Unscannable # Could not scan Spam / EUQ # End-User Quarantine # CLI quarantine operations: quarantineconfig # Configure # GUI: Monitor > Policy, Virus, and Outbreak Quarantines
ATTACHMENT / FILE INVESTIGATION#
# Find attachment by name grep -i "invoice.pdf" mail_logs grep "Attachment" mail_logs # Find by SHA256 (AMP) grep "abc123def456" amp/current # AMP verdict history grep "SHA256" amp/current | grep "MALICIOUS" # File analysis (sandbox) pending/complete grep "File Analysis" mail_logs # MID 12345 File 'sample.docx' sent for analysis # MID 12345 File Analysis verdict: MALICIOUS
URL / PHISHING INVESTIGATION#
# URL reputation decisions grep -E "URL.*reputation|URL.*category" mail_logs grep "rewritten" mail_logs # URL defense rewrites # Find messages with specific URL grep "http://suspicious.com" mail_logs # Phishing / Outbreak grep "Category=Phish" mail_logs grep "Threat Level" mail_logs
SEARCHING BY COMMON CRITERIA#
# By sender grep -i "from=<attacker@evil.com>" mail_logs grep -i "MAIL FROM" mail_logs | grep "evil.com" # By recipient grep -i "to=<victim@corp.lu>" mail_logs grep -i "RCPT TO" mail_logs | grep "corp.lu" # By subject grep -i "Subject:.*invoice" mail_logs # By IP grep "10.0.0.5" mail_logs grep "ICID.*10.0.0.5" mail_logs # By time (last hour) - tail + timestamps tail -n 10000 mail_logs | grep "$(date '+%a %b %d %H')"
LOG LINE ANATOMY#
# Typical mail_logs entries: # Connection accepted Mon Apr 14 10:23:45 2026 Info: New SMTP ICID 789012 interface Management (10.0.0.10) address 203.0.113.5 reverse dns host mail.sender.com verified yes # HAT decision Mon Apr 14 10:23:45 2026 Info: ICID 789012 ACCEPT SG UNKNOWNLIST match sbrs[-1.0:10.0] SBRS 2.1 # Message injected Mon Apr 14 10:23:46 2026 Info: Start MID 123456 ICID 789012 # Envelope Mon Apr 14 10:23:46 2026 Info: MID 123456 ICID 789012 From: <sender@example.com> Mon Apr 14 10:23:46 2026 Info: MID 123456 ICID 789012 RID 0 To: <user@corp.lu> # Subject Mon Apr 14 10:23:46 2026 Info: MID 123456 Subject 'Your invoice' # Verdicts Mon Apr 14 10:23:47 2026 Info: MID 123456 interim verdict using engine: CASE spam negative Mon Apr 14 10:23:47 2026 Info: MID 123456 antivirus negative Mon Apr 14 10:23:48 2026 Info: MID 123456 AMP file reputation verdict : CLEAN # Final action Mon Apr 14 10:23:48 2026 Info: MID 123456 queued for delivery Mon Apr 14 10:23:49 2026 Info: Delivery start DCID 345678 MID 123456 to RID [0] Mon Apr 14 10:23:49 2026 Info: Message done DCID 345678 MID 123456 to RID [0]
COMMON BLOCK SIGNATURES#
# Spam blocked "CASE spam positive" "interim verdict using engine: CASE spam positive" # Virus blocked "antivirus positive" "Dropped by antivirus" # AMP malicious "AMP file reputation verdict: MALICIOUS" "File Analysis verdict: MALICIOUS" # Outbreak blocked "Outbreak Filters: quarantined" "Threat Level=5" # Content filter drop "CF matched" "dropped by filter" # DLP block "DLP violation" "Action: QUARANTINE" # DMARC reject "DMARC: verification failed, action: reject" # Connection rejected "ICID .* REJECT" "TCPREFUSE"
QRADAR AQL QUERIES#
# Requires DSM: Cisco IronPort ESA / Cisco ESA
# Typical LogSource Type: "Cisco IronPort"
# All blocked emails last 24h
SELECT QIDNAME(qid), sourceip, destinationip, "Sender", "Recipient",
"Subject", "Verdict", "Action"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND "Action" ILIKE '%block%' OR "Action" ILIKE '%drop%'
OR "Action" ILIKE '%quarantine%' OR "Action" ILIKE '%reject%'
LAST 24 HOURS
# Messages with AMP MALICIOUS verdict
SELECT devicetime, "Sender", "Recipient", "Subject",
"Attachment Name", "SHA256", "Verdict"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND "Verdict" ILIKE '%MALICIOUS%'
LAST 7 DAYS
# Anti-spam positives
SELECT devicetime, sourceip, "Sender", "Recipient", "Subject",
"Spam Verdict"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND "Spam Verdict" ILIKE '%positive%'
LAST 24 HOURS
# DMARC failures
SELECT devicetime, "Sender", "Recipient", "Subject", "DMARC Result"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND "DMARC Result" ILIKE '%fail%'
LAST 24 HOURS
# Top senders of blocked mail
SELECT "Sender", COUNT(*) as cnt
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND ("Action" ILIKE '%block%' OR "Verdict" ILIKE '%MALICIOUS%')
GROUP BY "Sender"
ORDER BY cnt DESC
LAST 7 DAYS
# Top targeted recipients
SELECT "Recipient", COUNT(*) as cnt
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND "Verdict" ILIKE '%MALICIOUS%'
GROUP BY "Recipient"
ORDER BY cnt DESC
LAST 30 DAYS
# Outbound DLP violations
SELECT devicetime, "Sender", "Recipient", "DLP Policy", "Severity"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND "DLP Policy" IS NOT NULL
LAST 7 DAYS
# Connections rejected by HAT/SBRS
SELECT sourceip, COUNT(*) as rejects
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND "Action" ILIKE '%REJECT%'
GROUP BY sourceip
ORDER BY rejects DESC
LAST 24 HOURS
# Track specific MID
SELECT *
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND "MID" = '123456'
LAST 7 DAYS
# Messages with URL rewrites (URL defense triggered)
SELECT "Sender", "Recipient", "Subject", "URL"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND payload ILIKE '%rewritten%'
LAST 24 HOURS
# Outbreak Filter hits
SELECT devicetime, "Sender", "Recipient", "Subject",
"Threat Level", "Threat Category"
FROM events
WHERE LOGSOURCETYPENAME(devicetype) = 'Cisco IronPort'
AND "Threat Level" >= 3
LAST 24 HOURS
MICROSOFT DEFENDER XDR / SENTINEL (KQL)#
# For hybrid environments where ESA fronts Exchange Online
# Correlate ESA verdicts with Defender for Office 365
# EmailEvents - blocked/quarantined
EmailEvents
| where Timestamp > ago(24h)
| where DeliveryAction in ("Blocked", "Junked", "Replaced")
| project Timestamp, SenderFromAddress, RecipientEmailAddress,
Subject, DeliveryAction, ThreatTypes, DetectionMethods
# Malicious attachments
EmailAttachmentInfo
| where Timestamp > ago(7d)
| where ThreatTypes has "Malware"
| project Timestamp, FileName, SHA256, ThreatTypes, FileType
| join kind=inner EmailEvents on NetworkMessageId
| project Timestamp, SenderFromAddress, RecipientEmailAddress,
Subject, FileName, SHA256, ThreatTypes
# URL clicks on malicious links
UrlClickEvents
| where Timestamp > ago(7d)
| where ThreatTypes != ""
| project Timestamp, AccountUpn, Url, ThreatTypes, ActionType,
IsClickedThrough
# Users who clicked through warnings
UrlClickEvents
| where Timestamp > ago(30d)
| where IsClickedThrough == true
| where ThreatTypes contains "Phish" or ThreatTypes contains "Malware"
| summarize Clicks=count(), Urls=make_set(Url) by AccountUpn
# Phishing delivered to inbox
EmailEvents
| where Timestamp > ago(24h)
| where ThreatTypes has "Phish"
| where DeliveryLocation == "Inbox"
| project Timestamp, SenderFromAddress, RecipientEmailAddress,
Subject, ThreatTypes, DeliveryAction
# Correlate email with endpoint detonation
EmailAttachmentInfo
| where Timestamp > ago(7d)
| where ThreatTypes has "Malware"
| join kind=inner (
DeviceFileEvents
| where Timestamp > ago(7d)
) on SHA256
| project Timestamp, RecipientEmailAddress, DeviceName,
FileName, SHA256, ActionType
# Emails from specific sender domain
EmailEvents
| where Timestamp > ago(7d)
| where SenderFromDomain == "suspicious-domain.com"
| project Timestamp, SenderFromAddress, RecipientEmailAddress,
Subject, DeliveryAction, ThreatTypes
# DMARC/DKIM/SPF failures
EmailEvents
| where Timestamp > ago(24h)
| where AuthenticationDetails has_any ("fail", "softfail")
| project Timestamp, SenderFromAddress, RecipientEmailAddress,
Subject, AuthenticationDetails, DeliveryAction
# Top phishing targets
EmailEvents
| where Timestamp > ago(30d)
| where ThreatTypes has "Phish"
| summarize Attempts=count() by RecipientEmailAddress
| order by Attempts desc
| take 20
# ZAP (Zero-hour Auto Purge) events
EmailPostDeliveryEvents
| where Timestamp > ago(7d)
| where Action == "ZAP"
| project Timestamp, RecipientEmailAddress, Subject, ThreatTypes,
Action, ActionResult
# Correlate ESA block with Defender (same SHA256)
// Run in Defender after identifying SHA256 from ESA logs
let esa_sha = "abc123def456...";
union EmailAttachmentInfo, DeviceFileEvents
| where SHA256 == esa_sha
| project Timestamp, Type=case(
$table == "EmailAttachmentInfo", "Email",
$table == "DeviceFileEvents", "Endpoint",
"Unknown"),
FileName, DeviceName=coalesce(DeviceName,""),
Recipient=coalesce(RecipientEmailAddress,"")
# Impersonation attempts (display-name spoof)
EmailEvents
| where Timestamp > ago(7d)
| where ThreatTypes has_any ("Impersonation", "Spoof")
| project Timestamp, SenderDisplayName, SenderFromAddress,
RecipientEmailAddress, Subject, ThreatTypes
INVESTIGATION WORKFLOWS#
WORKFLOW 1: User reports phishing#
1. Get: sender, subject, timestamp, recipient 2. ESA Message Tracking -> find MID 3. CLI: grep "MID xxxxx" mail_logs 4. Check verdicts: SPF/DKIM/DMARC, Spam, AV, AMP, Outbreak, URL 5. Get SHA256 of attachments, URLs 6. Pivot to Defender: EmailAttachmentInfo / UrlClickEvents by SHA256/URL 7. Check other recipients: same sender / subject / SHA256 8. Check endpoint execution: DeviceFileEvents / DeviceProcessEvents 9. If delivered: trigger remediation (Purge + ZAP) 10. Block: sender domain, URL, file hash at ESA + Defender
WORKFLOW 2: DLP outbound investigation#
1. ESA Message Tracking -> DLP policy hits 2. grep "DLP violation" mail_logs 3. Identify: policy, severity, sender, recipient, data type 4. Review message content in quarantine (if severity allows) 5. Interview user / verify business justification 6. QRadar: correlate with user activity (badge, VPN, file access) 7. Document in ticket; escalate if CRITICAL severity
WORKFLOW 3: Mass delivery failure#
1. CLI: hoststatus <destination> 2. tophosts to see destination queue 3. grep "Soft bounced\|Bounced" mail_logs | tail 4. Check: DNS, destination MTA status, our IP reputation 5. Check SBRS of our outbound IP (talosintelligence.com) 6. Check DMARC/SPF/DKIM on our sending domain
WORKFLOW 4: Suspected compromised internal sender#
1. grep "from=<user@corp.lu>" mail_logs | wc -l 2. Compare baseline volume 3. Check: unusual subjects, external recipients, bulk patterns 4. grep MID matching suspicious messages 5. Pivot Defender: AADSignInEventsBeta for the user 6. Check: impossible travel, new device, MFA anomalies 7. Trigger: password reset, session revoke, MFA re-enroll
QUICK REFERENCE#
grep "MID 12345" mail_logs Track message grep "ICID 789" mail_logs Track connection grep "CASE spam positive" mail_logs Spam blocks grep "antivirus positive" mail_logs AV blocks grep "AMP.*MALICIOUS" mail_logs AMP blocks grep "Outbreak Filters" mail_logs Outbreak blocks grep "CF matched" mail_logs Content filter grep "DLP violation" mail_logs DLP blocks grep "DMARC.*fail" mail_logs DMARC failures grep "ICID.*REJECT" mail_logs HAT rejections grep "queued for delivery" mail_logs Accepted grep "quarantined to" mail_logs Quarantined grep "Dropped" mail_logs Silently dropped findevent Interactive search tophosts Destination queue hoststatus <host> Host details displayalerts Recent alerts rate Real-time rate
COMMON VERDICT STRINGS (BOOKMARK)#
CASE spam positive / negative / suspect antivirus positive / negative / unscannable AMP file reputation verdict: CLEAN / MALICIOUS / UNKNOWN / UNSCANNABLE File Analysis verdict: MALICIOUS / CLEAN / PENDING Outbreak Filters: quarantined / scheduled / scanned CF matched / MF matched DLP violation: <policy> severity CRITICAL / HIGH / MEDIUM / LOW SPF: pass / fail / softfail / neutral / none DKIM: pass / fail / none DMARC: pass / fail action: none / quarantine / reject SBRS: <score> or None HAT: ACCEPT / REJECT / TCPREFUSE / RELAY
FINAL DISPOSITION KEYWORDS#
queued for delivery Accepted to queue Delivered Success Bounced Hard bounce (5xx) Soft bounced Temp bounce (4xx) quarantined to Policy Policy quarantine quarantined to Virus Virus quarantine quarantined to Outbreak Outbreak quarantine quarantined to File Analysis AMP sandbox quarantined to Spam Spam quarantine Dropped Silent drop Rejected SMTP reject TCPREFUSE Connection refused