Add OneNote Fileextensions to the Exchange Online Malware Filter
Hi All,
I've heard from OneNote Phishing in the last few Months. That seems to be a new way of Attack.
Sadly i don't know the exact details of that Attack.
What came to my mind was to block OneNote Attachments in the Malware Filter.
Microsoft: Besserer Schutz vor riskantem OneNote-Phishing geplant
Also Microsoft want's to improve here according to the M 365 Roadmap
data:image/s3,"s3://crabby-images/73fd7/73fd71e263786a6c5b67960b9509dc7ecec22dc0" alt=""
I've checked the OneNote file Extensions on my Computer
data:image/s3,"s3://crabby-images/6d798/6d7983fd8dbd0a333c6fb6e6415b256896de66d3" alt=""
Microsoft OneNote File Extensions according to thefile.org
data:image/s3,"s3://crabby-images/c5bb8/c5bb8ca90b43f5ee0b2451bf0790927525f194e5" alt=""
Let's go to work. List the Malware Filter Policys in Exchange Online
Connect-ExchangeOnline
Get-MalwareFilterPolicy | ft Name
data:image/s3,"s3://crabby-images/d1cd7/d1cd7fdb648d7a02606d3b2cab32a0f485c71816" alt=""
Look at the Details. As you can see the Extensions are in the FileTypes Attribute (without dot before the Extension).
Get-MalwareFilterPolicy -Identity ICEWOLFMalwarefilterPolicy-01
data:image/s3,"s3://crabby-images/de9db/de9dbe44cd7fb1cbbafeca4476a55fc50d433211" alt=""
Let's add the OneNote File Extensions
$FileTypes = (Get-MalwareFilterPolicy -Identity ICEWOLFMalwarefilterPolicy-01).FileTypes
$FileTypes.Count
$FileTypes.Add("one")
$FileTypes.Add("onepkg")
$FileTypes.Add("onetoc")
$FileTypes.Add("pwi")
$FileTypes.Add("sig")
$FileTypes.Add("onechache")
$FileTypes.Add("onetmp")
$FileTypes.Add("onetoc")
Set-MalwareFilterPolicy -Identity ICEWOLFMalwarefilterPolicy-01 -FileTypes $FileTypes
$FileTypes.Count
$FileTypes.Add("one")
$FileTypes.Add("onepkg")
$FileTypes.Add("onetoc")
$FileTypes.Add("pwi")
$FileTypes.Add("sig")
$FileTypes.Add("onechache")
$FileTypes.Add("onetmp")
$FileTypes.Add("onetoc")
Set-MalwareFilterPolicy -Identity ICEWOLFMalwarefilterPolicy-01 -FileTypes $FileTypes
data:image/s3,"s3://crabby-images/57b7a/57b7af18f775514ca496ffcf46451ea6a87c3746" alt=""
As you can see the Filetypes are now in the Policy
data:image/s3,"s3://crabby-images/24180/241808fb468474de6f8fe5370e17b83fa78c5859" alt=""
Regards
Andres Bohren
data:image/s3,"s3://crabby-images/41807/418077381cbae835a1a7d22a0fcf1948f7a73b5b" alt=""