247 lines
9.8 KiB
PowerShell
247 lines
9.8 KiB
PowerShell
# Settings
|
|
|
|
$UserPrincipalName = "admin@constructtechservices.com"
|
|
|
|
$EnableExternalTagging = $true
|
|
$ExternalTaggingAllowedDomains = @{Add="emberkom.com", "ef-capital.com", "elysionconstruction.com", "elysioncreations.com", "tesseractrentals.com", "arcadiapropertyservices.com"}
|
|
|
|
$BypassSenderDomains = @(
|
|
"emberkom.com",
|
|
"notify.emberkom.com",
|
|
"ef-capital.com",
|
|
"elysionconstruction.com",
|
|
"elysioncreations.com",
|
|
#"constructtechservices.com",
|
|
"tesseractrentals.com",
|
|
"arcadiapropertyservices.com"
|
|
)
|
|
|
|
$SetImpersonationRule = $true
|
|
$SetSuspiciousEmailRule = $true
|
|
$SetGeneralExternalEmailRule = $true
|
|
|
|
# Connect to EOL
|
|
Connect-ExchangeOnline -UserPrincipalName $UserPrincipalName
|
|
|
|
# Enable/disable external tagging for Outlook clients
|
|
If ( (Get-ExternalInOutlook).Enabled -ne $EnableExternalTagging ) {
|
|
If ( $EnableExternalTagging ) {
|
|
Write-Output "Enabling external email tagging"
|
|
} Else {
|
|
Write-Output "Disabling external email tagging"
|
|
}
|
|
If ( $EnableExternalTagging -and $ExternalTaggingAllowedDomains ) {
|
|
Set-ExternalInOutlook -Enabled $EnableExternalTagging -AllowList $ExternalTaggingAllowedDomains
|
|
} Else {
|
|
Set-ExternalInOutlook -Enabled $EnableExternalTagging
|
|
}
|
|
}
|
|
|
|
# Impersonation Rule
|
|
If ( $SetImpersonationRule ) {
|
|
$ImpersonationEmailDisclaimerTitle = "Warning:"
|
|
$ImpersonationEmailDisclaimerText = "This appears to be a fradulent email attempting to impersonate someone inside your organization. Do not click on links or open attachments unless you are certain this email is safe."
|
|
|
|
$ImpersonationRuleName = "Impersonation Warning"
|
|
$ImpersonationDisclaimer = '<table border=0 cellspacing=0 cellpadding=0 align="left" width="100%">
|
|
<tr>
|
|
<td style="background:#dc3232;padding:5pt 2pt 5pt 2pt"></td>
|
|
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#fff8e5;padding:5pt 4pt 5pt 12pt;word-wrap:break-word">
|
|
<div style="color:#222222;">
|
|
<span style="color:#222; font-weight:bold;">' + $ImpersonationEmailDisclaimerTitle + ' </span>' + $ImpersonationEmailDisclaimerText + '
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
<br/>'
|
|
|
|
# Set the transport rule for user impersonation
|
|
$DisplayNames = (Get-EXOMailbox -ResultSize Unlimited -RecipientTypeDetails UserMailbox).DisplayName
|
|
$ImpersonationTransportRule = Get-TransportRule | Where-Object { $_.Name -eq $ImpersonationRuleName }
|
|
If ( $ImpersonationTransportRule ) {
|
|
Write-Output "Updating transport rule: ${ImpersonationRuleName}"
|
|
Set-TransportRule -Identity $ImpersonationRuleName `
|
|
-FromScope NotInOrganization `
|
|
-SentToScope InOrganization `
|
|
-HeaderMatchesMessageHeader From `
|
|
-HeaderMatchesPatterns $DisplayNames `
|
|
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
|
-ApplyHtmlDisclaimerLocation Prepend `
|
|
-ApplyHtmlDisclaimerText $ImpersonationDisclaimer `
|
|
-ApplyHtmlDisclaimerFallbackAction Wrap
|
|
Write-Output "Transport rule updated"
|
|
} Else {
|
|
Write-Output "Creating transport rule: ${ImpersonationRuleName}"
|
|
New-TransportRule -Name $ImpersonationRuleName `
|
|
-FromScope NotInOrganization `
|
|
-SentToScope InOrganization `
|
|
-HeaderMatchesMessageHeader From `
|
|
-HeaderMatchesPatterns $DisplayNames `
|
|
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
|
-ApplyHtmlDisclaimerLocation Prepend `
|
|
-ApplyHtmlDisclaimerText $ImpersonationDisclaimer `
|
|
-ApplyHtmlDisclaimerFallbackAction Wrap
|
|
Write-Output "Transport rule created"
|
|
}
|
|
}
|
|
|
|
# Suspicious Email Rule
|
|
If ( $SetSuspiciousEmailRule ) {
|
|
$SuspiciousEmailDisclaimerTitle = "Caution:"
|
|
$SuspiciousEmailDisclaimerText = "This is a suspicious email from outside your organization. Please be cautious when clicking links or opening attachments."
|
|
|
|
$SuspiciousEmailRuleName = "Suspicious Email Warning"
|
|
$SuspiciousEmailDisclaimer = '<table border=0 cellspacing=0 cellpadding=0 align="left" width="100%">
|
|
<tr>
|
|
<td style="background:#ffb900;padding:5pt 2pt 5pt 2pt"></td>
|
|
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#fff8e5;padding:5pt 4pt 5pt 12pt;word-wrap:break-word">
|
|
<div style="color:#222222;">
|
|
<span style="color:#222; font-weight:bold;">' + $SuspiciousEmailDisclaimerTitle + ' </span>' + $SuspiciousEmailDisclaimerText + '
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
<br />'
|
|
|
|
# This list is copied from: https://github.com/SwiftOnSecurity/PhishingRegex/blob/master/PhishingRegex.txt
|
|
$SuspiciousEmailPatterns = @(
|
|
'blocked\ your?\ online',
|
|
'suspicious\ activit',
|
|
'updated?\ your\ account\ record',
|
|
'Securely\ \S{3,4}\ one(\ )?drive',
|
|
'Securely\ \S{3,4}\ drop(\ )?box',
|
|
'Securely\ \S{3,4}\ Google\ Drive',
|
|
'sign\ in\S{0,7}(with\ )?\ your\ email\ address',
|
|
'Verify\ your\ ID\s',
|
|
'dear\ \w{3,8}(\ banking)?\ user',
|
|
'chase\S{0,10}\.html"',
|
|
'\b(?<=https?://)(www\.)?icloud(?!\.com)',
|
|
'(?<![\x00\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4A\x4B\x4C\x4D\x4E\x4F\x50\x51\x52\x53\x54\x55\x56\x57\x58\x59\x5A])appie\W',
|
|
'/GoogleDrive/',
|
|
'/googledocs?/',
|
|
'/Dropfile/',
|
|
'limit\ (and\ suspend\ )?your\ account',
|
|
'\b(?<=https?://)(?!www\.paypal\.com/)\S{0,40}pa?y\S{0,2}al(?!\S*\.com/)',
|
|
'sitey\.me',
|
|
'myfreesites\.net',
|
|
'/uploadfile/',
|
|
'/\S{0,3}outloo\S{0,2}k\S{1,3}\W',
|
|
'\b(?<=https?://webmail\.)\S{0,40}webmail\w{0,3}(?!/[0-9])(?!\S{0,40}\.com/)',
|
|
'owaportal',
|
|
'outlook\W365',
|
|
'/office\S{0,3}365/',
|
|
'-icloud\Wcom',
|
|
'pyapal',
|
|
'/docu\S{0,3}sign\S{1,4}/',
|
|
'/helpdesk/',
|
|
'pay\Sa\S{0,2}login',
|
|
'/natwest/',
|
|
'/dro?pbo?x/',
|
|
'%20paypal',
|
|
'\.invoice\.php',
|
|
'security-?err',
|
|
'/newdropbox/',
|
|
'/www/amazon',
|
|
'simplefileupload',
|
|
'security-?warning',
|
|
'-(un)?b?locked',
|
|
'//helpdesk(?!\.)',
|
|
'\.my-free\.website',
|
|
'mail-?update',
|
|
'\.yolasite\.com',
|
|
'//webmail(?!\.)',
|
|
'\.freetemplate\.site',
|
|
'\.sitey\.me',
|
|
'\.ezweb123\.com',
|
|
'\.tripod\.com',
|
|
'\.myfreesites\.net',
|
|
'mailowa',
|
|
'-icloud',
|
|
'icloud-',
|
|
'contabo\.net',
|
|
'\.xyz/',
|
|
'ownership\ validation\ (has\ )?expired',
|
|
'icloudcom',
|
|
'\w\.jar(?=\b)',
|
|
'/https?/www/',
|
|
'\.000webhost(app)?\.com',
|
|
'is\.gd/',
|
|
'\.weebly\.com',
|
|
'\.wix\.com',
|
|
'tiny\.cc/',
|
|
'\.joburg',
|
|
'\.top/'
|
|
)
|
|
|
|
# Set the transport rule for suspicious emails
|
|
$SuspiciousEmailRule = Get-TransportRule | Where-Object { $_.Name -eq $SuspiciousEmailRuleName }
|
|
If ( $SuspiciousEmailRule ) {
|
|
Write-Output "Updating transport rule: ${SuspiciousEmailRuleName}"
|
|
Set-TransportRule -Identity $SuspiciousEmailRuleName `
|
|
-FromScope NotInOrganization `
|
|
-SentToScope InOrganization `
|
|
-SubjectOrBodyMatchesPatterns $SuspiciousEmailPatterns `
|
|
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
|
-ApplyHtmlDisclaimerLocation Prepend `
|
|
-ApplyHtmlDisclaimerText $SuspiciousEmailDisclaimer `
|
|
-ApplyHtmlDisclaimerFallbackAction Wrap
|
|
Write-Output "Transport rule updated"
|
|
} Else {
|
|
Write-Output "Creating transport rule: ${SuspiciousEmailRuleName}"
|
|
New-TransportRule -Name $SuspiciousEmailRuleName `
|
|
-FromScope NotInOrganization `
|
|
-SentToScope InOrganization `
|
|
-SubjectOrBodyMatchesPatterns $SuspiciousEmailPatterns `
|
|
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
|
-ApplyHtmlDisclaimerLocation Prepend `
|
|
-ApplyHtmlDisclaimerText $SuspiciousEmailDisclaimer `
|
|
-ApplyHtmlDisclaimerFallbackAction Wrap
|
|
Write-Output "Transport rule created"
|
|
}
|
|
}
|
|
|
|
# General External Email Rule
|
|
If ( $SetGeneralExternalEmailRule ) {
|
|
$GeneralExternalEmailDisclaimerTitle = "Notice:"
|
|
$GeneralExternalEmailDisclaimerText = "This email came from outside your organization. Please be sure you know the recipient or were expecting this email before clicking on links or opening attachments."
|
|
|
|
$GeneralExternalEmailRuleName = "External Email Warning"
|
|
$GeneralExternalEmailDisclaimer = '<table border=0 cellspacing=0 cellpadding=0 align="left" width="100%">
|
|
<tr>
|
|
<td style="background:#00A0d2;padding:5pt 2pt 5pt 2pt"></td>
|
|
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#e5f5fa;padding:5pt 4pt 5pt 12pt;word-wrap:break-word">
|
|
<div style="color:#222222;">
|
|
<span style="color:#222; font-weight:bold;">' + $GeneralExternalEmailDisclaimerTitle + ' </span>' + $GeneralExternalEmailDisclaimerText + '
|
|
</div>
|
|
</td>
|
|
</tr>
|
|
</table>
|
|
<br/>'
|
|
|
|
# Set the transport rule for all external emails
|
|
$GeneralExternalEmailRule = Get-TransportRule | Where-Object { $_.Name -eq $GeneralExternalEmailRuleName }
|
|
If ( $GeneralExternalEmailRule ) {
|
|
Write-Output "Updating transport rule: ${GeneralExternalEmailRuleName}"
|
|
Set-TransportRule -Identity $GeneralExternalEmailRuleName `
|
|
-FromScope NotInOrganization `
|
|
-SentToScope InOrganization `
|
|
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
|
-ApplyHtmlDisclaimerLocation Prepend `
|
|
-ApplyHtmlDisclaimerText $GeneralExternalEmailDisclaimer `
|
|
-ApplyHtmlDisclaimerFallbackAction Wrap
|
|
Write-Output "Transport rule updated"
|
|
} Else {
|
|
Write-Output "Creating transport rule: ${GeneralExternalEmailRuleName}"
|
|
New-TransportRule -Name $GeneralExternalEmailRuleName `
|
|
-FromScope NotInOrganization `
|
|
-SentToScope InOrganization `
|
|
-ExceptIfSenderDomainIs $BypassSenderDomains `
|
|
-ApplyHtmlDisclaimerLocation Prepend `
|
|
-ApplyHtmlDisclaimerText $GeneralExternalEmailDisclaimer `
|
|
-ApplyHtmlDisclaimerFallbackAction Wrap
|
|
Write-Output "Transport rule created"
|
|
}
|
|
}
|
|
|
|
# Close connection to EOL
|
|
Disconnect-ExchangeOnline -Confirm:$false | Out-Null |