The regular expression can be something like :
/name=[^>]*\.(bat|cmd|exe|com|pif|reg|scr|vb|vbe|vbs)/
to match attachments whose filenames end with extensions signifying potentially dangerous Windows executables.
The action can be like :
REJECT
to simply reject mail matching the expression, or :
REDIRECT spam@yourdomain.com
To forward mail to another address.