nexxai / CryptoBlocker

A script to deploy File Server Resource Manager and associated scripts to block infected users
GNU General Public License v2.0
200 stars 73 forks source link

Inclusion of .docm - vulnerable filetype, sure, but it's an MS Office file type? #82

Open mcdodd opened 5 years ago

mcdodd commented 5 years ago

Over the last 8-10 days we've started seeing false-positive reports from FSRM because *.docm has been added to the filter list.

This is the Word macro-enabled document type - it's a vulnerable document type (no question), but Word provides other (policy-led) measures to control/limit that vulnerability.

Inclusion has led to false positives which undermine confidence in the notifications from the list. This, in turn, could weaken engineer resolve to check each one properly.

This 'feels' like a step beyond the objective of the filter list. *.docm files can be routinely generated/used by authorised users, whereas previously filter items have been targeted at being specific indicators of ransomware/malware.

Any chance you can change *.docm to something more specific?

While I'm here, thanks for maintaining this tool. It's invaluable.

Thanks Matthew