Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: v20240117a
Table of Contents

20232024-101-1017

Status
colour

...

Yellow
title

...

Status
colourYellow
titlenew threat category
QR Code

Since the start of 2023, INKY has incorporated QR Code detection methods into our processing. Due to a recent surge in QR Code-related threats, we've now introduced a distinct QR Code threat category, rather than keeping it as a behind-the-scenes flag. This category is enabled by default. However, it can be toggled on/off at: https://app.inkyphishfence.com/settings/analysis.

If INKY identifies a QR code in a message, that message will be marked with a "QR Code" result and assigned a "Caution" or "Danger" threat level, based on other suspicious content found.

Admins also have the flexibility to customize the QR code policy text and its associated URL. By default, emails with detected QR Codes will include the specific notification text below.

Beware of unexpected QR codes from unknown senders.

Preview
- New User Center

In the coming weeks INKY will roll out a new User Dashboard as the default where users can manage their Blocked Sender Addresses, Blocked Sender Domains, Personal Allow List, Graymail Handling, and Signature Settings.

You’ll soon see a new pink banner at the top of the current User Dashboard with a link to the new User Center.

...

Selecting the banner will take you to the new User Center that streamlines the user experience and provides a single application for all users and admins within INKY.

...

Please reach out to support@inky.com if you experience any issues with the new User Center or feedback@inky.com with any thoughts!

Status
colourPurple
titleFeature Enhancement
-

...

Status
colourRed
titlenew threat category
Blocked Top-Level Domain

In addition to the current blocked sender location functionality, we’ve added the ability to block top level domains (TLDs) and public suffixes (e.g., co.uk). This blocking mechanism is enforced against the following mail properties.

  • MAIL FROM envelope address

  • From or Reply-To header address

  • Link URLs

  • Image URLs

...

Additionally, there's a new feature to "Automatically block ccTLDs (Country Code Top-Level Domains) based on the chosen Blocked Sender Location." For instance, if Montenegro (.me) is selected, its country code will also be considered a Blocked Top-Level Domain, alongside the Blocked Sender Location.

...

Admin Management via Directory Groups from M365 and Google Workspace

If your team has the Domain and Directory Access API enabled, https://app.inkyphishfence.com/settings/api-access, you’ll now be able to add M365 or Google Workspace groups directly to the Admin Management page. This allows members to access INKY at the level of access assigned to the group.

This was previously handled through manually added the Tenant ID and Group ID directly to the page - this enhancement now allows you to scroll the list of groups within your tenant to directly select the intended group.

Follow the steps found here to get started: https://inkyops.atlassian.net/wiki/spaces/AG2/pages/1800438086/Admin+Management#Add-Admin-by-Active-Directory-Groups

...

You can also assign groups to an organization level. Organizations are denoted with the “Skyscraper” icon, options listed when you have an organization selected affect all of the child teams - including which users can manage a child team. Groups pulled at an organization level come from the base team that’s created to build an organization.

For example: polvocapital-o365 is the base teamid used for INKY’s honeypot account. In the picture above there is no “Skyscraper” icon next to “Polvo Capital” in the top left corner of the picture - this means we’re looking at the base team.

In the picture below you’ll see fewer settings options and the “Skyscraper” icon next to “Polvo Capital” - these means we’re looking at the organization level. The groups in the Tenant Group dropdown are the same as the base team because the organization inherits them. This allows MSPs (organizations) the ability to assign groups to specific INKY roles, giving members access at the appropriate level to all child teams.

...