{"id":7939,"date":"2024-05-23T23:54:45","date_gmt":"2024-05-23T23:54:45","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=7939"},"modified":"2024-05-23T23:54:47","modified_gmt":"2024-05-23T23:54:47","slug":"mimecast-letting-through-high-risk-cred-phishing-emails","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/mimecast-letting-through-high-risk-cred-phishing-emails","title":{"rendered":"Mimecast letting through High Risk Cred Phishing emails"},"content":{"rendered":"\n<p>Recently a customer Mimecast configuration let an email through marked as <\/p>\n\n\n\n<p><strong>High Risk Cred Phishing<\/strong><\/p>\n\n\n\n<p>Turns out their Spam Detection Action was set to Tag Headers instead of Hold for Review!<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-12.png\"><img loading=\"lazy\" decoding=\"async\" width=\"271\" height=\"57\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-12.png\" alt=\"\" class=\"wp-image-7940 img-responsive\"\/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-13.png\"><img loading=\"lazy\" decoding=\"async\" width=\"535\" height=\"484\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-13.png\" alt=\"\" class=\"wp-image-7941 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-13.png 535w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2024\/05\/image-13-300x271.png 300w\" sizes=\"auto, (max-width: 535px) 100vw, 535px\" \/><\/a><\/figure>\n\n\n\n<p>Mimecast Spam Scanning uses a combination of proprietary technology in conjunction with third party technology partners in order to provide a layered spam scanning approach. While our engines are taking updates from our technology partners 24 hours a day, we also write our own spam signatures in house. Signatures written for our &#8220;spam&#8221; engine are often built to detect phishing and malware \u2014 much more than just spam.<br>Mimecast looks at the body, formatting, source, header and any URIs in the body when scanning an email. Based on patterns, or combinations of patterns, a spam score is applied. There are tens of thousands of patterns. For instance, things like sending to undisclosed recipients, using SMTP Authentication, URL Shorteners, or SPF\/DKIM\/DMARC failures can add points to the spam score. However, none of them would be enough for a hold on their own. When patterns like this are found in conjunction with other spam characteristics, the score increases. Based on the findings or a combination of elements Mimecast will make a decision and based on that an email is allowed through, held or rejected. Our spam engine works by giving each email a spam score.<\/p>\n\n\n\n<p><br>Relaxed 7-27 = hold<\/p>\n\n\n\n<p> Moderate 5-27 = hold <\/p>\n\n\n\n<p>Aggressive 3-27 = hold<\/p>\n\n\n\n<p><br>Emails would need to be scanned for them to be blocked. Emails scoring 28 or higher are always rejected<br>The only way to block the emails would be to change the spam scanning configuration. It is best practice to have your Spam Detection Action set to &#8220;Hold for Review&#8221;<br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently a customer Mimecast configuration let an email through marked as High Risk Cred Phishing Turns out their Spam Detection Action was set to Tag Headers instead [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-7939","post","type-post","status-publish","format-standard","hentry","category-research"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7939","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=7939"}],"version-history":[{"count":1,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7939\/revisions"}],"predecessor-version":[{"id":7942,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/7939\/revisions\/7942"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=7939"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=7939"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=7939"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}