M365EXO-042: Direct download links scanned for malware (MS.EXO.15.2)
- Plataforma
- Entra ID / M365
- Categoría
- Advanced Threat Protection
- Severidad
- High
- Pilar de Zero Trust
- Applications & Workloads (peso 2)
- Fixtures de referencia
- 3
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- baseline
Qué comprueba
SCuBA MS.EXO.15.2 recommends that direct download links be scanned for malware. Links in mail may point directly to malware downloads. Real-time scanning of the destination file when a user clicks a direct download link blocks the download if malware is detected, preventing device infection.
Valor recomendado
Safe Links (or comparable) policy with real-time URL/file scanning enabled (ScanUrls = True)
Remediación
Enable real-time scanning of URLs and direct-download destinations in the Safe Links or comparable policy so files behind links are scanned for malware at click time. Apply the policy to all users. Verify the option to deliver only after scanning completes is configured where appropriate to maximize protection.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| clean | PASS |
| known-bad | WARN |
| throttled | Not Assessed |
Mapeos a marcos de referencia
- NIST SP 800-53
- SI-3
- MITRE ATT&CK
- T1566.002