CTD-000134

Microsoft Entra tenant has Exchange Organization without mail-flow rules restricting attachments with executables

Medium
Entra ID Exchange Online
Execution Initial Access
v17

Signature Identity

CTD-000134
Threat ID
17
Version
IOE
Indicator Type

Threat Description

This threat detects all tenants that do not have mail-flow rules restricting attachments with executables.

The threat actor may execute code or a script using the attachments in the email.

MITRE ATT&CK: Attack Tactics

Execution Initial Access

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

  1. Log into the Exchange Admin Center.
  2. Navigate to the Mail flow section.
  3. Click Mail flow.
  4. Select Rules.
  5. Click the + icon to add a new rule.
  6. Select Create a new rule.
  7. Set Rule Conditions:
    1. Name the rule: e.g., Block executable attachments.
    2. Apply this rule if: Select Any attachment and then File extension includes these words.
    3. Specify words or phrases: Enter the file extensions you want to block. Learn more. Add each extension separately by clicking Add after each one.
  8. Set the Rule Actions by selecting Block the message, then reject the message with an explanation, or Delete the message without notifying anyone.
  9. Provide a reason in case of rejecting the message, e.g. Attachments with executable files are not allowed.
  10. Under the Except if section, add Exceptions (Optional) in case certain users or domains should be exempt from this rule: e.g., exempt internal users or specific trusted partners.
  11. Click Save to finalize the rule.
  12. Ensure the rule is enabled. You may need to toggle the rule from Disabled to Enabled.
  13. Review and save the rule.

Frequently Asked Questions

What does Microsoft Entra tenant has Exchange Organization without mail-flow rules restricting attachments with executables mean?

Your Exchange Online organization lacks a critical rule to block executable file attachments in emails, allowing attackers to potentially execute code or scripts via email attachments.

The absence of this rule enables attackers to execute malicious code or scripts via email attachments, but does not grant them administrative control. This capability supports potential compromise and places the issue in the middle of the severity scale.

An attacker can send an email with an executable file attachment, which will be executed by the recipient's email client, potentially leading to malware deployment or other malicious activities. This allows attackers to execute code or scripts on the target system, enabling further exploitation and persistence.

Cayosoft Guardian continuously monitors your Exchange Online organization for missing mail-flow rules that restrict executable file attachments, flagging the issue when such a rule is absent.

Cayosoft Guardian alerts administrators to create and enable a rule in the Exchange Admin Center that blocks executable file attachments, limiting the potential for attackers to execute malicious code or scripts via email. This helps provide visibility into the issue and supports investigation and response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Exchange Online
Themes
Mail flow rules
Attack Tactics
Execution Initial Access
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical