Sanitize Microsoft OneNote files through content disarm and reconstruction
This information is also available in the FortiOS 7.6 Administration Guide: |
FortiOS antivirus supports Microsoft OneNote files through the content disarm and reconstruction (CDR) feature. This allows the FortiGate to sanitize these files by detecting and removing active content, such as hyperlinks and embedded media, while preserving the text. This feature provides an additional tool for network administrators to protect users from malicious documents.
To configure CDR for Microsoft OneNote files:
-
Go to Security Profiles > AntiVirus.
-
Select a proxy-based antivirus profile and click Edit.
-
In APT Protection Options, enable Content Disarm and Reconstruction.
-
Enable Apply CDR to office files.
-
Click OK.
-
Review the logs:
-
In Log & Report > Security Events > Logs, the content disarm of Microsoft OneNote files are listed.
-
In the logs, the content disarm of Microsoft OneNote files are listed:
1: date=2024-02-15 time=13:41:29 eventtime=1708033288658288261 tz="-0800" logid="0205009240" type="utm" subtype="virus" eventtype="content-disarm" level="warning" vd="vdom1" policyid=1 poluuid="12703e08-bc4a-51ed-a0bd-185c7e368bef" policytype="policy" epoch=1499437875 eventid=2 msg="File was disarmed by Content Disarm engine." action="content-disarmed" service="HTTP" sessionid=4321 srcip=10.1.100.18 dstip=172.16.200.44 srcport=47632 dstport=80 srccountry="Reserved" dstcountry="Reserved" srcintf="port2" srcintfrole="undefined" dstintf="port1" dstintfrole="undefined" srcuuid="dfcbd5b6-bc49-51ed-1617-cf3ea170cee5" dstuuid="dfcbd5b6-bc49-51ed-1617-cf3ea170cee5" proto=6 direction="incoming" filename="with_multiple_insert_files.one" checksum="8d077b7" url="http://172.16.200.44/content_disarm/OneNote/with_multiple_insert_files.one" profile="av" analyticscksum="4fab69475ede27c359ba7f1b3eab2555a1faa471e2664a4d8e48e31e67333110" contentdisarmed="disarmed" cdrcontent="office-embedded-object" rawdata="[RESP] Content-Type=application/onenote" crscore=10 craction=2 crlevel="medium" 2: date=2024-02-15 time=13:40:48 eventtime=1708033248160303337 tz="-0800" logid="0205009240" type="utm" subtype="virus" eventtype="content-disarm" level="warning" vd="vdom1" policyid=1 poluuid="12703e08-bc4a-51ed-a0bd-185c7e368bef" policytype="policy" epoch=1499437874 eventid=1 msg="File was disarmed by Content Disarm engine." action="content-disarmed" service="HTTP" sessionid=4287 srcip=10.1.100.18 dstip=172.16.200.44 srcport=50110 dstport=80 srccountry="Reserved" dstcountry="Reserved" srcintf="port2" srcintfrole="undefined" dstintf="port1" dstintfrole="undefined" srcuuid="dfcbd5b6-bc49-51ed-1617-cf3ea170cee5" dstuuid="dfcbd5b6-bc49-51ed-1617-cf3ea170cee5" proto=6 direction="incoming" filename="OneNote2016_hyperlink.one" checksum="2c986f08" url="http://172.16.200.44/content_disarm/OneNote/OneNote2016_hyperlink.one" profile="av" analyticscksum="400c3b0d1c608536906e589862c04fb574676752595d08617101003e06f7baf0" contentdisarmed="disarmed" cdrcontent="office-hyperlink" rawdata="[RESP] Content-Type=application/onenote" crscore=10 craction=2 crlevel="medium"
-