@ -1,3 +1,4 @@
{% if SCAN_MACROS == 'True' %}
OLETOOLS_MACRO_MRAPTOR {
expression = "(OLETOOLS_A & OLETOOLS_W) | (OLETOOLS_A & OLETOOLS_X) | (OLETOOLS_W & OLETOOLS_X)";
message = "Rejected (malicious macro - mraptor)";
@ -10,3 +11,4 @@ OLETOOLS_MACRO_SUSPICIOUS {
policy = "leave";
score = 20.0;
}
{% endif %}
oletools {
# default olefy settings
servers = "{{ OLETOOLS_ADDRESS }}"
@ -60,3 +61,4 @@ oletools {
slk = "slk";
# local.d/external_services_group.conf
description = "Oletools content rules";
@ -36,3 +37,4 @@ symbols = {
one_shot = true;
},