> Source: [sk115252](https://support.checkpoint.com/results/sk/sk115252)

# sk115252 - Threat Emulation logs show "Detect" for e-mail attachments instead of "Prevent" when Threat Extraction blade is also enabled

| Property | Value |
|----------|-------|
| Solution ID | sk115252 |
| Date Created | 2016-12-28 |
| Last Modified | 2018-10-04 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- SmartView Tracker / SmartLog logs from Threat Emulation blade show malicious files being detected in e-mail attachments rather than being prevented (as per Threat Prevention profile) in the following scenario:

1. Both the Threat Emulation and Threat Extraction blades are enabled on the Security Gateway
2. Mail Transfer Agent (MTA) is enabled and configured on the Security Gateway
3. SandBlast Parallel Extraction Hotfix is installed on the Security Gateway  
   (refer to [sk108074](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108074); this hotfix was integrated into R77.30 Jumbo Hotfix Accumulator since *Take_128*).
4. E-mails with attachments are sent over SMTP

## Cause

When Threat Extraction blade finishes scanning of an attachment inside an e-mail before Threat Emulation blade finishes the emulation process, the Mail Transfer Agent (MTA) passes the e-mail as-is.

This generates the "Detect" log, as there was no actual file to "Prevent".

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
