Skip to content
English
  • There are no suggestions because the search field is empty.

Reported Threats 2.0

Click below for a full screen walkthrough video.
▶️ Reported Threats 2.0

 

Active Threat Manager has been redesigned to be an even more powerful tool. Below are the updates and improvements.

  • Unified Case-Based Dashboard: Redesigned Reported Threats experience groups emails by sender and subject, allowing admins to judge clusters of look-alike emails at once rather than individual messages.
  • Advanced Threat Search: Admins can now launch a domain-wide sweep directly from any reported threat case, pre-populated with sender and subject data to quickly identify related messages.
  • Action Audit Log: Maintains a chronological, read-only record of all actions taken on a case, providing full transparency on whether interventions were performed by an admin or CyberNut.

1. Log in to CyberNut at http://admin.cybernut.com

2. Select Reported Threats.

3. If you have any NEW reported threats when logging in to CyberNut they will appear immediately or you can view them by selecting Reported Threats on the left side panel.

4. As you remediate any reported threats they will be organized into these categories for future reference.

5. Here you can filter your search by days.

6. Select "Needs Review" to see all the reported threats you have not remediated yet.

7. Click on the row for any of the reported threats to review them.

8. Click on "View Email" to inspect the message.

9. Here you can preview the email or click on "Headers" to view email metadata.

10. Click on "Remediate" to take action on threats.

11. Select the appropriate option to Remediate the email(s).

12. Click here to mark the email(s) as Spam.

13. Once you select what remediation you want an email template will appear if enabled in CyberNut settings. Click Mark Spam and it will send an email back to the person(s) that reported it.

14. Click here to mark the email(s) as Safe.

15. Click here to mark the email(s) as Ignore.

 

16. Click here to escalate the email(s) for further review.

17. Click on "Reporters" to see who reported threats.

18. Click on "View Email" to review the message.

19. Here you can preview the email and see the Headers.

20. Click on "Accounts secured" to check protected accounts.

21. Click on "Audit Log" to view activity history.

22. Click here to use the Advanced Threat Search to see all the users who received the email.

23. Both the "Date" and "Subject?" fields will be prefilled.

24. Click on "Search" to begin your query.

25. Go directly to "Advanced Threat Search" in the left side panel at anytime.

26. Click the "Date" field to select a timeframe.

27. Enter a Recipient Email here if needed.

28. Enter a Subject here if needed. Even part of the subject will work.

29. Enter a Message ID here to be more exact in your search.

30. Click on "Search" to run your query.

31. Click the subject to view details.

32. Check the box beside the email to take action.

33. Click on "Action" to see available options.

34. Here you have a variety of actions you can take.

35. Once you select an action a message will appear giving full details of the action to be taken.

36. Click "Compromised Accounts" to check security breaches.

37. Here you can view if you have any compromised accounts.

38. Click the case to review the details.

39. Here you will find all the details related to the email that will help you in your investigation.

40. Click on "ATT recommended actions" to view recommendations.

41. Click on "Key Evidence" to see detailed evidence.

42. Click on "Reporters" to check reporter information.

43. Click on "Accounts secured" to confirm protections applied.

44. Click on "Audit Log" to review action history.

45. Take action and remediate as needed as shown earlier.

46. Congratulations!

You've learned about Reported Threats 2.0. Visit this article to learn more about the Automatic Threat Terminator (ATT) that makes the threats manager even better.