The EDR Email Protection provides a dedicated Mail Threat Protection component that secures organizational email communication at the point of use the client endpoint. Email remains the primary delivery vector for phishing, ransomware, and malware; this module is engineered to inspect every inbound and outbound message and its attachments in real time, neutralizing threats before they reach the user or propagate across the wider corporate network.
1.Mail Threat Protection — Client-Side Interception and Scanning
1.1 Dedicated Mail Threat Protection component: The Net Protector EDR Email Protection embeds a dedicated Mail Threat Protection engine that operates locally on every protected endpoint. It is delivered and governed centrally as an EDR policy, so the same protection profile applies uniformly across all managed client machines.
1.2 On-endpoint interception: Email is intercepted and scanned directly on the client machine as messages are sent and received, rather than relying solely on a perimeter or gateway. This ensures protection is enforced even for endpoints operating outside the corporate network, including remote and roaming users.
1.3 Bidirectional inspection: Both incoming and outgoing email flows are inspected. Inbound messages are scanned to block threats entering the organization, while outbound messages are scanned to prevent the endpoint from being used to distribute malicious content or exfiltrate data.
1.4 Message body and attachment scanning: Each message is examined in full — the email body, embedded links, and all attachments — so that threats concealed within file attachments or hyperlinks are detected at the endpoint before delivery to the user or transmission to an external recipient.
1.5 Email logging for audit and forensics: All email activity processed by the component is logged. These records support security monitoring, incident investigation, and audit/compliance reporting, providing a verifiable trail of inspected and acted-upon messages.
1.6 Centralized policy enforcement: Administrators configure the Mail Threat Protection behavior from the EDR management console and push it to endpoints as policy, ensuring consistent, tamper-resistant enforcement of email security controls across the estate.
2. Threat Prevention — Phishing, Ransomware and Malware
2.1 Anti-phishing through link scanning: Every URL contained in an email is scanned to identify suspicious or malicious links. Phishing attempts that direct users to credential-harvesting or fraudulent sites are detected and blocked, defeating the threat before the user can interact with it.
2.2 Ransomware and malware blocking via attachment scanning: All attachments are scanned by the Net Protector scanning engine, which is built to detect known and emerging malware families. Ransomware payloads, trojans, droppers, and other malicious files carried by email are identified and prevented from reaching the endpoint.
2.3 Pre-delivery enforcement: Detection and action occur in line with message processing — before a malicious message or attachment reaches the user’s mailbox or is delivered onward. Stopping the threat at this stage prevents the initial compromise that typically precedes lateral movement.
2.4 Containment of the wider network: Because outbound email is also inspected, a compromised or misused endpoint is prevented from propagating malware or phishing to internal and external recipients. This limits the blast radius of an incident and protects the broader corporate network.
2.5 Configurable response actions: Administrators can select how detected threats are handled. “Reports Only” mode generates detailed detection reports without blocking, suited to monitoring or pilot phases, while “Block and Report” mode actively blocks offending email according to the configured security settings and simultaneously generates reports for analysis.
2.6 Attachment-handling controls: Threat exposure from attachments is further reduced through two complementary modes: “Allow all except blocklist,” which permits attachments except those explicitly blocked, and “Block all except allowlist,” which blocks all attachments except those explicitly approved — enabling a strict, default-deny posture for high-risk environments.
2.7 Reporting for response and audit: Detection events are recorded and reported, giving security teams the visibility needed to investigate phishing, ransomware, and malware attempts and to demonstrate the effectiveness of email controls during audits.
3. Real-Time Monitoring via Standard Client Protocols
3.1 Protocol-level monitoring: The Mail Threat Protection component actively monitors email traffic at the standard client protocol level, covering the protocols used by desktop email clients for sending and retrieving mail:
- SMTP (Simple Mail Transfer Protocol) — outbound message transmission.
- POP3 (Post Office Protocol v3) — inbound message retrieval.
- IMAP (Internet Message Access Protocol) — inbound mailbox access and synchronization.
- NNTP (Network News Transfer Protocol) — newsgroup message traffic.
3.2 Real-time, in-line inspection: Messages and their attachments are inspected as soon as they are received or sent. Monitoring is continuous and in-line with mail flow, so detection and enforcement happen during transmission rather than after the message has been delivered.
3.3 Attachment inspection on every transaction: For each monitored transaction, attachments are scanned alongside the message body and links, ensuring malicious files cannot bypass inspection regardless of the client protocol in use.
3.4 Coverage of inbound and outbound traffic: Both directions of mail flow are monitored — inbound retrieval (POP3/IMAP) and outbound transmission (SMTP) — providing complete, real-time coverage of the endpoint’s standard email activity.
3.5 Outbound traffic controls: For outgoing mail, advanced controls allow message traffic to be governed by policy: domain-based control restricts sending to predefined business domains, and email-based control restricts sending to approved recipient addresses — blocking unauthorized outbound communication as it occurs.
3.6 Continuous endpoint logging: Monitored email transactions are logged in real time, providing an up-to-date record of message traffic and attachment activity for security operations and audit.
4. Office 365 Cloud Protection — Exchange Online, OneDrive and SharePoint Online
4.1 Exchange Online mailbox protection: The solution allows Office 365 Exchange Online mailboxes to be brought under protection, extending mail threat inspection — phishing, malicious links, and malware-bearing attachments — to cloud-hosted mailboxes managed through the organization’s Office 365 tenant.
4.2 OneDrive user protection: Files belonging to OneDrive users managed through Office 365 can be inspected, so that malicious or non-compliant content stored in users’ cloud drives is identified and acted upon.
4.3 SharePoint Online site protection: SharePoint Online sites managed through Office 365 can be protected, extending content inspection to documents and files shared and collaborated on across team and organisational sites.
4.4 Detection of critical information in cloud storage: The solution detects critical information held in files located in Office 365 cloud storage locations, supporting identification of sensitive or regulated data residing in Exchange Online, OneDrive, and SharePoint Online.
4.5 Centralized management: Protection of Office 365 mailboxes, OneDrive users, and SharePoint Online sites is administered centrally, consistent with the policy-driven management model of the Net Protector EDR platform.