You can pull information for a message in search detections using the following parameters:
- From (
- From Name
- To (any) (
- To Name (any)
- Cc (any)
- Subject (any)
- Sent DateTime (formatted as
- Received DateTime (formatted as
- sha256 (attachments)
- ssdeep (attachments)
- name (attachments)
- md5 (attachments)
- Reason(s) for Detection
In addition to the message parameters above, you can use these additional detection search strings:
For disposition-specific submission searches, refer to Service Addresses in the Area 1 dashboard.
For Area 1 Horizon Enterprise customers, detections search would index for a period of 12 months and rotate over to a rolling 12-month period.
For Area 1 Horizon Advantage customers, detections search would index for three months and rotate over to a rolling 3-month period.