added RMM shim script to repo
This commit is contained in:
@@ -0,0 +1,247 @@
|
||||
# Settings
|
||||
|
||||
$UserPrincipalName = "admin@constructtechservices.com"
|
||||
|
||||
$EnableExternalTagging = $true
|
||||
$ExternalTaggingAllowedDomains = @{Add="emberkom.com", "ef-capital.com", "elysionconstruction.com", "elysioncreations.com", "tesseractrentals.com", "arcadiapropertyservices.com"}
|
||||
|
||||
$BypassSenderDomains = @(
|
||||
"emberkom.com",
|
||||
"notify.emberkom.com",
|
||||
"ef-capital.com",
|
||||
"elysionconstruction.com",
|
||||
"elysioncreations.com",
|
||||
#"constructtechservices.com",
|
||||
"tesseractrentals.com",
|
||||
"arcadiapropertyservices.com"
|
||||
)
|
||||
|
||||
$SetImpersonationRule = $true
|
||||
$SetSuspiciousEmailRule = $true
|
||||
$SetGeneralExternalEmailRule = $true
|
||||
|
||||
# Connect to EOL
|
||||
Connect-ExchangeOnline -UserPrincipalName $UserPrincipalName
|
||||
|
||||
# Enable/disable external tagging for Outlook clients
|
||||
If ( (Get-ExternalInOutlook).Enabled -ne $EnableExternalTagging ) {
|
||||
If ( $EnableExternalTagging ) {
|
||||
Write-Output "Enabling external email tagging"
|
||||
} Else {
|
||||
Write-Output "Disabling external email tagging"
|
||||
}
|
||||
If ( $EnableExternalTagging -and $ExternalTaggingAllowedDomains ) {
|
||||
Set-ExternalInOutlook -Enabled $EnableExternalTagging -AllowList $ExternalTaggingAllowedDomains
|
||||
} Else {
|
||||
Set-ExternalInOutlook -Enabled $EnableExternalTagging
|
||||
}
|
||||
}
|
||||
|
||||
# Impersonation Rule
|
||||
If ( $SetImpersonationRule ) {
|
||||
$ImpersonationEmailDisclaimerTitle = "Warning:"
|
||||
$ImpersonationEmailDisclaimerText = "This appears to be a fradulent email attempting to impersonate someone inside your organization. Do not click on links or open attachments unless you are certain this email is safe."
|
||||
|
||||
$ImpersonationRuleName = "Impersonation Warning"
|
||||
$ImpersonationDisclaimer = '<table border=0 cellspacing=0 cellpadding=0 align="left" width="100%">
|
||||
<tr>
|
||||
<td style="background:#dc3232;padding:5pt 2pt 5pt 2pt"></td>
|
||||
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#fff8e5;padding:5pt 4pt 5pt 12pt;word-wrap:break-word">
|
||||
<div style="color:#222222;">
|
||||
<span style="color:#222; font-weight:bold;">' + $ImpersonationEmailDisclaimerTitle + ' </span>' + $ImpersonationEmailDisclaimerText + '
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<br/>'
|
||||
|
||||
# Set the transport rule for user impersonation
|
||||
$DisplayNames = (Get-EXOMailbox -ResultSize Unlimited -RecipientTypeDetails UserMailbox).DisplayName
|
||||
$ImpersonationTransportRule = Get-TransportRule | Where-Object { $_.Name -eq $ImpersonationRuleName }
|
||||
If ( $ImpersonationTransportRule ) {
|
||||
Write-Output "Updating transport rule: ${ImpersonationRuleName}"
|
||||
Set-TransportRule -Identity $ImpersonationRuleName `
|
||||
-FromScope NotInOrganization `
|
||||
-SentToScope InOrganization `
|
||||
-HeaderMatchesMessageHeader From `
|
||||
-HeaderMatchesPatterns $DisplayNames `
|
||||
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
||||
-ApplyHtmlDisclaimerLocation Prepend `
|
||||
-ApplyHtmlDisclaimerText $ImpersonationDisclaimer `
|
||||
-ApplyHtmlDisclaimerFallbackAction Wrap
|
||||
Write-Output "Transport rule updated"
|
||||
} Else {
|
||||
Write-Output "Creating transport rule: ${ImpersonationRuleName}"
|
||||
New-TransportRule -Name $ImpersonationRuleName `
|
||||
-FromScope NotInOrganization `
|
||||
-SentToScope InOrganization `
|
||||
-HeaderMatchesMessageHeader From `
|
||||
-HeaderMatchesPatterns $DisplayNames `
|
||||
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
||||
-ApplyHtmlDisclaimerLocation Prepend `
|
||||
-ApplyHtmlDisclaimerText $ImpersonationDisclaimer `
|
||||
-ApplyHtmlDisclaimerFallbackAction Wrap
|
||||
Write-Output "Transport rule created"
|
||||
}
|
||||
}
|
||||
|
||||
# Suspicious Email Rule
|
||||
If ( $SetSuspiciousEmailRule ) {
|
||||
$SuspiciousEmailDisclaimerTitle = "Caution:"
|
||||
$SuspiciousEmailDisclaimerText = "This is a suspicious email from outside your organization. Please be cautious when clicking links or opening attachments."
|
||||
|
||||
$SuspiciousEmailRuleName = "Suspicious Email Warning"
|
||||
$SuspiciousEmailDisclaimer = '<table border=0 cellspacing=0 cellpadding=0 align="left" width="100%">
|
||||
<tr>
|
||||
<td style="background:#ffb900;padding:5pt 2pt 5pt 2pt"></td>
|
||||
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#fff8e5;padding:5pt 4pt 5pt 12pt;word-wrap:break-word">
|
||||
<div style="color:#222222;">
|
||||
<span style="color:#222; font-weight:bold;">' + $SuspiciousEmailDisclaimerTitle + ' </span>' + $SuspiciousEmailDisclaimerText + '
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<br />'
|
||||
|
||||
# This list is copied from: https://github.com/SwiftOnSecurity/PhishingRegex/blob/master/PhishingRegex.txt
|
||||
$SuspiciousEmailPatterns = @(
|
||||
'blocked\ your?\ online',
|
||||
'suspicious\ activit',
|
||||
'updated?\ your\ account\ record',
|
||||
'Securely\ \S{3,4}\ one(\ )?drive',
|
||||
'Securely\ \S{3,4}\ drop(\ )?box',
|
||||
'Securely\ \S{3,4}\ Google\ Drive',
|
||||
'sign\ in\S{0,7}(with\ )?\ your\ email\ address',
|
||||
'Verify\ your\ ID\s',
|
||||
'dear\ \w{3,8}(\ banking)?\ user',
|
||||
'chase\S{0,10}\.html"',
|
||||
'\b(?<=https?://)(www\.)?icloud(?!\.com)',
|
||||
'(?<![\x00\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4A\x4B\x4C\x4D\x4E\x4F\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5A])appie\W',
|
||||
'/GoogleDrive/',
|
||||
'/googledocs?/',
|
||||
'/Dropfile/',
|
||||
'limit\ (and\ suspend\ )?your\ account',
|
||||
'\b(?<=https?://)(?!www\.paypal\.com/)\S{0,40}pa?y\S{0,2}al(?!\S*\.com/)',
|
||||
'sitey\.me',
|
||||
'myfreesites\.net',
|
||||
'/uploadfile/',
|
||||
'/\S{0,3}outloo\S{0,2}k\S{1,3}\W',
|
||||
'\b(?<=https?://webmail\.)\S{0,40}webmail\w{0,3}(?!/[0-9])(?!\S{0,40}\.com/)',
|
||||
'owaportal',
|
||||
'outlook\W365',
|
||||
'/office\S{0,3}365/',
|
||||
'-icloud\Wcom',
|
||||
'pyapal',
|
||||
'/docu\S{0,3}sign\S{1,4}/',
|
||||
'/helpdesk/',
|
||||
'pay\Sa\S{0,2}login',
|
||||
'/natwest/',
|
||||
'/dro?pbo?x/',
|
||||
'%20paypal',
|
||||
'\.invoice\.php',
|
||||
'security-?err',
|
||||
'/newdropbox/',
|
||||
'/www/amazon',
|
||||
'simplefileupload',
|
||||
'security-?warning',
|
||||
'-(un)?b?locked',
|
||||
'//helpdesk(?!\.)',
|
||||
'\.my-free\.website',
|
||||
'mail-?update',
|
||||
'\.yolasite\.com',
|
||||
'//webmail(?!\.)',
|
||||
'\.freetemplate\.site',
|
||||
'\.sitey\.me',
|
||||
'\.ezweb123\.com',
|
||||
'\.tripod\.com',
|
||||
'\.myfreesites\.net',
|
||||
'mailowa',
|
||||
'-icloud',
|
||||
'icloud-',
|
||||
'contabo\.net',
|
||||
'\.xyz/',
|
||||
'ownership\ validation\ (has\ )?expired',
|
||||
'icloudcom',
|
||||
'\w\.jar(?=\b)',
|
||||
'/https?/www/',
|
||||
'\.000webhost(app)?\.com',
|
||||
'is\.gd/',
|
||||
'\.weebly\.com',
|
||||
'\.wix\.com',
|
||||
'tiny\.cc/',
|
||||
'\.joburg',
|
||||
'\.top/'
|
||||
)
|
||||
|
||||
# Set the transport rule for suspicious emails
|
||||
$SuspiciousEmailRule = Get-TransportRule | Where-Object { $_.Name -eq $SuspiciousEmailRuleName }
|
||||
If ( $SuspiciousEmailRule ) {
|
||||
Write-Output "Updating transport rule: ${SuspiciousEmailRuleName}"
|
||||
Set-TransportRule -Identity $SuspiciousEmailRuleName `
|
||||
-FromScope NotInOrganization `
|
||||
-SentToScope InOrganization `
|
||||
-SubjectOrBodyMatchesPatterns $SuspiciousEmailPatterns `
|
||||
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
||||
-ApplyHtmlDisclaimerLocation Prepend `
|
||||
-ApplyHtmlDisclaimerText $SuspiciousEmailDisclaimer `
|
||||
-ApplyHtmlDisclaimerFallbackAction Wrap
|
||||
Write-Output "Transport rule updated"
|
||||
} Else {
|
||||
Write-Output "Creating transport rule: ${SuspiciousEmailRuleName}"
|
||||
New-TransportRule -Name $SuspiciousEmailRuleName `
|
||||
-FromScope NotInOrganization `
|
||||
-SentToScope InOrganization `
|
||||
-SubjectOrBodyMatchesPatterns $SuspiciousEmailPatterns `
|
||||
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
||||
-ApplyHtmlDisclaimerLocation Prepend `
|
||||
-ApplyHtmlDisclaimerText $SuspiciousEmailDisclaimer `
|
||||
-ApplyHtmlDisclaimerFallbackAction Wrap
|
||||
Write-Output "Transport rule created"
|
||||
}
|
||||
}
|
||||
|
||||
# General External Email Rule
|
||||
If ( $SetGeneralExternalEmailRule ) {
|
||||
$GeneralExternalEmailDisclaimerTitle = "Notice:"
|
||||
$GeneralExternalEmailDisclaimerText = "This email came from outside your organization. Please be sure you know the recipient or were expecting this email before clicking on links or opening attachments."
|
||||
|
||||
$GeneralExternalEmailRuleName = "External Email Warning"
|
||||
$GeneralExternalEmailDisclaimer = '<table border=0 cellspacing=0 cellpadding=0 align="left" width="100%">
|
||||
<tr>
|
||||
<td style="background:#00A0d2;padding:5pt 2pt 5pt 2pt"></td>
|
||||
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#e5f5fa;padding:5pt 4pt 5pt 12pt;word-wrap:break-word">
|
||||
<div style="color:#222222;">
|
||||
<span style="color:#222; font-weight:bold;">' + $GeneralExternalEmailDisclaimerTitle + ' </span>' + $GeneralExternalEmailDisclaimerText + '
|
||||
</div>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<br/>'
|
||||
|
||||
# Set the transport rule for all external emails
|
||||
$GeneralExternalEmailRule = Get-TransportRule | Where-Object { $_.Name -eq $GeneralExternalEmailRuleName }
|
||||
If ( $GeneralExternalEmailRule ) {
|
||||
Write-Output "Updating transport rule: ${GeneralExternalEmailRuleName}"
|
||||
Set-TransportRule -Identity $GeneralExternalEmailRuleName `
|
||||
-FromScope NotInOrganization `
|
||||
-SentToScope InOrganization `
|
||||
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
||||
-ApplyHtmlDisclaimerLocation Prepend `
|
||||
-ApplyHtmlDisclaimerText $GeneralExternalEmailDisclaimer `
|
||||
-ApplyHtmlDisclaimerFallbackAction Wrap
|
||||
Write-Output "Transport rule updated"
|
||||
} Else {
|
||||
Write-Output "Creating transport rule: ${GeneralExternalEmailRuleName}"
|
||||
New-TransportRule -Name $GeneralExternalEmailRuleName `
|
||||
-FromScope NotInOrganization `
|
||||
-SentToScope InOrganization `
|
||||
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
||||
-ApplyHtmlDisclaimerLocation Prepend `
|
||||
-ApplyHtmlDisclaimerText $GeneralExternalEmailDisclaimer `
|
||||
-ApplyHtmlDisclaimerFallbackAction Wrap
|
||||
Write-Output "Transport rule created"
|
||||
}
|
||||
}
|
||||
|
||||
# Close connection to EOL
|
||||
Disconnect-ExchangeOnline -Confirm:$false | Out-Null
|
||||
Reference in New Issue
Block a user