TheHive-Project / Cortex-Analyzers

Cortex Analyzers Repository
https://TheHive-Project.github.io/Cortex-Analyzers/
GNU Affero General Public License v3.0
423 stars 372 forks source link

[FR] Added capabilities/features for Microsoft Defender O365 #1246

Closed padey closed 5 months ago

padey commented 5 months ago

I have slightly revised the existing "Microsoft Defender Office 365" responder and added a new function. Previously, this responder was intended to block malicious sender domains and email addresses. However, the "Tenant Allow/Blocklist" has even more features that I wanted to use.

The following have been revised:

Example "MSDefenderOffice365_block_1_0" -> "MSDefenderOffice365blocksender_1_0"

New feature:

A possible use case of this feature: QR phishing links can be blocked directly if the Defender for iOS has been installed. In my test, after blocking the domain, it was almost immediately no longer possible to access the URL on the iPhone.