MS.EXO.9.2v1 - The attachment filter SHOULD attempt to determine the true file type and assess the file extension.

Information

Users can change a file extension at the end of a file name (e.g., notepad.exe to notepad.txt) to obscure the actual file type. Verifying the file type and checking that this matches the designated file extension can help detect instances where the file extension was changed.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Any product meeting the requirements outlined in this baseline policy may be used. If the agency uses Microsoft Defender, see the following implementation steps for [enabling preset security policies](https://github.com/cisagov/ScubaGear/tree/v1.5.0/PowerShell/ScubaGear/baselines/defender.md#implementation), which attempt to determine the true file type and assess the file extension.

See Also

https://github.com/cisagov/ScubaGear/tree/v1.5.0/

Item Details

Category: SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|CA-7, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|IA-2, 800-53|SI-4

Plugin: microsoft_azure

Control ID: 5197c858fd2ce0245b40ba46af4d1b8e33cc0964a601e788f8a79b7878b562c1