Skip to main content
Version: 2.1.1-preview

ORCA.110 - Internal Sender notifications are disabled.

Overview​

Notifying internal senders about malware detected in email messages could have negative impact. An adversary with access to an already compromised mailbox may use this information to verify effectiveness of malware detection.

Remediation action​

Disable notifying internal senders of malware detection.

Test Metadata​

FieldValue
Test IDORCA.110
SeverityMedium
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA110
TagsEXO, ORCA, ORCA.110

Source​

  • Pester test: tests/orca/Test-ORCA110.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA110.ps1