Skip to main content
Version: 2.1.0

ORCA.179 - Safe Links is enabled intra-organization.

Overview

Phishing attacks are not limited from external users. Commonly, when one user is compromised, that user can be used in a process of lateral movement between different accounts in your organization. Configuring Safe Links so that internal messages are also re-written can assist with lateral movement using phishing. The built-in policy is ignored in this check, as it only provides the minimum level of protection.

Remediation action

Enable Safe Links between internal users.

Test Metadata

FieldValue
Test IDORCA.179
SeverityMedium
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA179
TagsEXO, ORCA, ORCA.179

Source

  • Pester test: tests/orca/Test-ORCA179.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA179.ps1