Skip to main content
Version: 2.1.0

ORCA.110 - Internal Sender notifications are disabled.

Overview

Notifying internal senders about malware detected in email messages could have negative impact. An adversary with access to an already compromised mailbox may use this information to verify effectiveness of malware detection.

Remediation action

Disable notifying internal senders of malware detection.

Test Metadata

FieldValue
Test IDORCA.110
SeverityMedium
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA110
TagsEXO, ORCA, ORCA.110

Source

  • Pester test: tests/orca/Test-ORCA110.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA110.ps1