diff --git a/config/branding.json b/config/branding.json index c09a76b..4a0cfdb 100644 --- a/config/branding.json +++ b/config/branding.json @@ -1,7 +1,9 @@ { "companyName": "CyberDrain", - "companyURL": "https://cyberdrain.com/", "productName": "Check", + "supportUrl": "", + "privacyPolicyUrl": "", + "aboutUrl": "", "version": "1.1.0", "description": "Protect against phishing attacks targeting Microsoft 365 login pages with enterprise-grade detection", "branding": { diff --git a/config/managed_schema.json b/config/managed_schema.json index fa279af..057b641 100644 --- a/config/managed_schema.json +++ b/config/managed_schema.json @@ -125,12 +125,6 @@ "description": "Company name to display in the extension", "type": "string", "default": "" - }, - "companyURL": { - "title": "Company URL", - "description": "Company URL used in the extension", - "type": "string", - "default": "https://cyberdrain.com/" }, "productName": { "title": "Product Name", @@ -145,6 +139,27 @@ "format": "email", "default": "" }, + "supportUrl": { + "title": "Support URL", + "description": "URL opened by the popup Support link", + "type": "string", + "format": "uri", + "default": "" + }, + "privacyPolicyUrl": { + "title": "Privacy URL", + "description": "URL opened by the popup Privacy link", + "type": "string", + "format": "uri", + "default": "" + }, + "aboutUrl": { + "title": "About URL", + "description": "URL opened by the popup About link", + "type": "string", + "format": "uri", + "default": "" + }, "primaryColor": { "title": "Primary Color", "description": "Primary theme color (hex code)", @@ -160,6 +175,82 @@ "default": "" } } + }, + "domainSquatting": { + "title": "Domain Squatting Detection", + "description": "Configuration for domain squatting detection to protect against typosquatting, homoglyphs, and combosquatting attacks. Enable/disable is controlled here (config/policy), and domains are automatically extracted from the URL allowlist.", + "type": "object", + "properties": { + "enabled": { + "title": "Enabled", + "description": "Enable or disable domain squatting detection", + "type": "boolean", + "default": true + }, + "deviationThreshold": { + "title": "Deviation Threshold", + "description": "Maximum number of character differences (Levenshtein distance) to trigger detection. Lower values are stricter.", + "type": "integer", + "minimum": 1, + "maximum": 5, + "default": 2 + }, + "algorithms": { + "title": "Detection Algorithms", + "description": "Enable or disable specific detection algorithms", + "type": "object", + "properties": { + "levenshtein": { + "title": "Levenshtein Distance", + "description": "Detect domains with small character differences", + "type": "boolean", + "default": true + }, + "homoglyph": { + "title": "Homoglyph Detection", + "description": "Detect confusable characters (e.g., 'a' vs 'а')", + "type": "boolean", + "default": true + }, + "typosquat": { + "title": "Typosquatting Detection", + "description": "Detect common typing mistakes and character swaps", + "type": "boolean", + "default": true + }, + "combosquat": { + "title": "Combosquatting Detection", + "description": "Detect domains with added prefixes/suffixes", + "type": "boolean", + "default": true + } + } + }, + "protectedDomains": { + "title": "Additional Protected Domains", + "description": "OPTIONAL: Additional domains to protect beyond those automatically extracted from the URL allowlist. Normally you should just add domains to the URL allowlist instead.", + "type": "array", + "items": { + "type": "string", + "title": "Domain", + "description": "Domain name to protect (e.g., 'company.com')" + }, + "default": [] + }, + "Action": { + "title": "Action", + "description": "Action to take when domain squatting is detected", + "type": "string", + "enum": ["block", "warn", "log"], + "default": "block" + }, + "logDetections": { + "title": "Log Detections", + "description": "Log all domain squatting detections to activity log", + "type": "boolean", + "default": true + } + } } } -} \ No newline at end of file +} diff --git a/docs/SUMMARY.md b/docs/SUMMARY.md index 6023154..38ff855 100644 --- a/docs/SUMMARY.md +++ b/docs/SUMMARY.md @@ -3,6 +3,10 @@ - [About](README.md) - [Firefox Support](firefox-support.md) +## Features + +- [Domain Squatting Detection](features/domain-squatting-detection.md) + ## Deployment - [Chrome/Edge Deployment Instructions](deployment/chrome-edge-deployment-instructions/README.md) diff --git a/docs/deployment/chrome-edge-deployment-instructions/windows/manual-deployment.md b/docs/deployment/chrome-edge-deployment-instructions/windows/manual-deployment.md index b4ce740..f26d209 100644 --- a/docs/deployment/chrome-edge-deployment-instructions/windows/manual-deployment.md +++ b/docs/deployment/chrome-edge-deployment-instructions/windows/manual-deployment.md @@ -10,6 +10,7 @@ This script is designed to deploy the extension to both Chrome and Edge. It is r 1. Review the Extension Configuration Settings and Custom Branding Settings variables and update those to your desired values. The current values in the script are the default values. Leaving any unchanged will set the defaults. 2. If you are leveraging a RMM that has the ability to define the variables in the deployment section of scripting, then you may be able to remove this section and enter the variable definitions into the RMM scripting pages. +3. For webhook deployment, configure `$enableGenericWebhook`, `$webhookUrl`, and `$webhookEvents` in the script. Supported events are documented in [Webhook Documentation](../../../webhooks.md). Download the Script from GitHub {% endtab %} diff --git a/docs/features/domain-squatting-detection.md b/docs/features/domain-squatting-detection.md new file mode 100644 index 0000000..d518f0c --- /dev/null +++ b/docs/features/domain-squatting-detection.md @@ -0,0 +1,232 @@ +# Domain Squatting Detection + +Domain squatting protection helps keep you safe from fake websites that try to trick you by using look-alike domain names. Attackers create these fake domains to steal your login credentials. + +## What is Domain Squatting? + +Domain squatting (sometimes called "typosquatting") is when attackers register website addresses that are intentionally similar to legitimate sites. For example: + +- `micros0ft.com` (using a zero instead of the letter O) +- `microsоft.com` (using a Cyrillic "о" that looks like an English "o") +- `login-microsoft.com` (adding extra words to a real domain) + +These fake sites often look exactly like the real Microsoft login page, but they're designed to capture your username and password. + +## How Check Protects You + +Check automatically watches for these fake domains using four smart detection methods: + +### 1. **Character Difference Detection** +Spots domains where characters are changed, missing, or swapped around. + +**Examples Check catches:** +- `microsft.com` → missing the letter "o" +- `micorsoft.com` → letters swapped ("or" instead of "ro") +- `microosoft.com` → extra letter added + +### 2. **Look-Alike Character Detection** +Finds domains using special characters that look similar to normal letters. + +**Examples Check catches:** +- `micrоsoft.com` → uses a Cyrillic "о" that looks like an English "o" +- `microsоft.com` → mixes different alphabet characters +- `micro𝐬oft.com` → uses special Unicode characters + +### 3. **Typing Mistake Detection** +Identifies domains based on common typing errors and keyboard slip-ups. + +**Examples Check catches:** +- `micrisoft.com` → finger slipped to nearby key +- `microssoft.com` → double-typed a letter +- `microosft.com` → typo mixing up letters + +### 4. **Suspicious Word Combination Detection** +Spots domains that add words before or after legitimate domains to look more official. + +**Examples Check catches:** +- `secure-microsoft.com` +- `login-microsoft-verify.com` +- `microsoft-auth.com` +- `official-microsoft-support.com` + +Common suspicious words attackers use: `login`, `secure`, `verify`, `official`, `support`, `auth`, `signin`, `portal` + +## What Domains Are Protected? + +Check protects **30+ popular domains** by default, including: + +**Microsoft Services:** +- microsoft.com, microsoftonline.com, office.com, outlook.com, onedrive.com, and more + +**Other Popular Services:** +- google.com, github.com, facebook.com, amazon.com, apple.com, paypal.com, and more + +**Plus: Your URL Allowlist** + +{% hint style="info" %} +**Unified Protection:** Check uses your [URL Allowlist](../settings/detection-rules.md#url-allowlist-regex-or-url-with-wildcards) for double protection. Any domains you add there are automatically protected from squatting attempts too! + +For example, if you add `https://yourcompany.com/*` to your allowlist, Check will also protect against fake domains like `yourcompany.net` or `your-company.com`. +{% endhint %} + +## How It Works in Practice + +When you visit a website, Check automatically: + +1. **Checks** if the domain looks similar to any protected domain +2. **Analyzes** using all four detection methods +3. **Warns** you if it finds a suspicious match +4. **Blocks** the page if it's clearly a phishing attempt + +You don't need to do anything - the protection works automatically in the background! + +## Configuration + +{% hint style="warning" %} +**For most users**: Domain squatting detection works automatically with default settings. You don't need to change anything! +{% endhint %} + +### Page Blocking Control + +Check has an **"Enable Page Blocking"** setting in the extension options that controls how suspicious pages are handled: + +- **Page Blocking Enabled** + **Action: "block"** = Page is completely blocked with full-page warning +- **Page Blocking Enabled** + **Action: "warn"** = Warning banner shown, page remains accessible +- **Page Blocking Disabled** = Warning banner shown regardless of action setting (never blocks) + +This gives you control over whether you want aggressive blocking or just warnings for suspicious domains. + +### For Advanced Users and IT Departments + +Domain squatting detection is configured in your detection rules file (not in the Settings UI). This follows the same pattern as other advanced security features like Rogue Apps Detection. + +#### How to Configure + +Edit your `rules/detection-rules.json` file to customize: + +**Enable/Disable Detection:** +```json +{ + "domain_squatting": { + "enabled": true, // Turn detection on/off + "action": "block" // Action when detected: "block" or "warn" + } +} +``` + +**Set Action Type:** +```json +{ + "domain_squatting": { + "action": "block" // "block" = full page block, "warn" = banner only + } +} +``` +Note: Page blocking also requires "Enable Page Blocking" to be turned ON in settings. + +**Adjust Sensitivity:** + "enabled": true + } +} +``` + +**Adjust Sensitivity** (how strict the checking is): +```json +{ + "domain_squatting": { + "deviation_threshold": 2 + } +} +``` +- Lower numbers (1) = Very strict, catches fewer variations +- Higher numbers (3-5) = More lenient, catches more variations +- Default is 2 (recommended for most organizations) + +**Choose Detection Methods:** +```json +{ + "domain_squatting": { + "algorithms": { + "levenshtein": true, + "homoglyph": true, + "typosquat": true, + "combosquat": true + } + } +} +``` + +You can turn individual detection methods on/off. We recommend keeping all four enabled for maximum protection. + +## For MSPs and Enterprise IT + +### Enterprise Policy Management + +Domain squatting detection can be managed through Group Policy (GPO) or Microsoft Intune, just like other Check settings. + +**What You Can Control via Policy:** +- Detection sensitivity (character difference threshold) +- Which detection methods are active +- Additional protected domains specific to your organization + +**What's in the Rules File:** +- Enable/disable domain squatting detection +- Default protected domains list +- Detection rules and patterns + +This separation gives you flexibility - you control the core security settings through your detection rules file, while still allowing policy-based customization for different clients or departments. + +### Adding Organization-Specific Domains + +{% hint style="info" %} +**Use the URL Allowlist!** + +The easiest way to protect your organization's domains is to add them to the URL Allowlist in Detection Rules settings. This automatically: +1. Prevents false positives on your internal sites +2. Protects those domains from squatting attempts +3. Works without modifying detection rules files +{% endhint %} + +**Example:** Adding `https://contoso.com/*` to your allowlist protects against fake domains like: +- `cont0so.com` (zero instead of o) +- `contos0.com` (zero at the end) +- `login-contoso.com` (suspicious prefix) + +### CIPP Reporting and Webhooks + +Domain squatting detections are automatically reported through your existing Check monitoring: + +- **Activity Logs**: View all domain squatting warnings and blocks +- **CIPP Integration**: Squatting detections appear in your CIPP logbook +- **Webhooks**: Configure webhooks to receive `domain_squatting_detected` events + +See [General Settings](../settings/general.md) for configuring reporting and webhooks. + +## Troubleshooting + +### "Check blocked a legitimate site" + +If Check blocks a site you trust: + +1. **Add it to your URL Allowlist** in Detection Rules settings +2. The site will be both allowed and protected from squatting +3. Report the false positive to help improve Check + +### "A phishing site wasn't detected" + +Domain squatting detection works alongside Check's other phishing protections. If a site gets through: + +1. Use "Report False Negative" if you encounter a phishing site +2. Check will update rules to catch it in the future +3. Your report helps protect the entire community + +### "Settings are grayed out" + +If you can't see or change domain squatting settings, your IT department has configured these centrally. This is normal for managed deployments - contact your IT team if you need adjustments. + +## Related Documentation + +- [Detection Rules](../settings/detection-rules.md) - Configure your URL allowlist +- [General Settings](../settings/general.md) - Set up reporting and webhooks +- [Enterprise Deployment](../deployment/) - Deploy Check across your organization +- [Creating Detection Rules](../advanced/creating-detection-rules.md) - Advanced rule customization diff --git a/docs/settings/branding.md b/docs/settings/branding.md index a4dce7b..9ba3fed 100644 --- a/docs/settings/branding.md +++ b/docs/settings/branding.md @@ -30,9 +30,11 @@ If some settings do not appear on your version, it means your organization's IT You can customize the following properties: 1. **Company Name** - Enter your organization's name. This appears in the extension interface and blocked page messages (displayed as "Protected by \[Company Name]"). -2. **Company URL** - Your company website URL (e.g., `https://yourcompany.com`). Used in extension branding and contact information. _(Firefox: required, Chrome/Edge: optional)_ -3. **Product Name** - What you want to call the extension (like "Contoso Security" instead of "Check"). This replaces the default "Check" branding throughout the interface. -4. **Support Email** - Where users should go for help. This email address is used in the "Contact Admin" button when phishing sites are blocked. +2. **Product Name** - What you want to call the extension (like "Contoso Security" instead of "Check"). This replaces the default "Check" branding throughout the interface. +3. **Support Email** - Where users should go for help. This email address is used in the "Contact Admin" button when phishing sites are blocked. +4. **Support URL** - URL opened by the popup **Support** link (for example, `https://support.yourcompany.com`). +5. **Privacy Policy URL** (`privacyPolicyUrl`) - URL opened by the popup **Privacy** link (for example, `https://yourcompany.com/privacy`). +6. **About URL** (`aboutUrl`) - URL opened by the popup **About** link. Leave empty to use the built-in extension About page. ## Visual Customization @@ -60,6 +62,9 @@ The branding preview shows you exactly how your customizations will appear to us * Logo (upload or provide URL) * Primary Color * Support Email + * Support URL + * Privacy Policy URL + * About URL 4. Click "Save" Your branding will be immediately applied to all components. @@ -78,7 +83,10 @@ For enterprise deployments using Windows Group Policy: "companyName": "Your Company", "logoUrl": "https://example.com/logo.png", "primaryColor": "#FF5733", - "supportEmail": "security@example.com" + "supportEmail": "security@example.com", + "supportUrl": "https://support.example.com", + "privacyPolicyUrl": "https://example.com/privacy", + "aboutUrl": "https://example.com/about" } } ``` @@ -106,9 +114,11 @@ For Firefox deployments, configure branding through the `policies.json` file: "check@cyberdrain.com": { "customBranding": { "companyName": "Your Company", - "companyURL": "https://yourcompany.com", "productName": "Security Extension", "supportEmail": "security@example.com", + "supportUrl": "https://support.example.com", + "privacyPolicyUrl": "https://example.com/privacy", + "aboutUrl": "https://example.com/about", "primaryColor": "#FF5733", "logoUrl": "https://example.com/logo.png" } @@ -137,7 +147,10 @@ For organizations using Microsoft Intune with Chrome/Edge: "companyName": "Your Company", "logoUrl": "https://example.com/logo.png", "primaryColor": "#FF5733", - "supportEmail": "security@example.com" + "supportEmail": "security@example.com", + "supportUrl": "https://support.example.com", + "privacyPolicyUrl": "https://example.com/privacy", + "aboutUrl": "https://example.com/about" } } ``` @@ -201,7 +214,6 @@ Enterprise policies always take precedence over manual settings. * Uses extension ID: `check@cyberdrain.com` * Configuration is managed through `policies.json` file -* Supports additional `companyURL` property * Policies file location varies by operating system ### Chrome & Edge @@ -290,7 +302,10 @@ Logo URL: https://assets.globalmfg.com/security/gmi-logo-48.png "productName": "Contoso Defender", "logoUrl": "https://contoso.com/assets/logo.png", "primaryColor": "#0078D4", - "supportEmail": "security@contoso.com" + "supportEmail": "security@contoso.com", + "supportUrl": "https://support.contoso.com", + "privacyPolicyUrl": "https://contoso.com/privacy", + "aboutUrl": "https://contoso.com/about" } } ``` @@ -305,11 +320,13 @@ Logo URL: https://assets.globalmfg.com/security/gmi-logo-48.png "check@cyberdrain.com": { "customBranding": { "companyName": "Contoso Corporation", - "companyURL": "https://contoso.com", "productName": "Contoso Defender", "logoUrl": "https://contoso.com/assets/logo.png", "primaryColor": "#0078D4", - "supportEmail": "security@contoso.com" + "supportEmail": "security@contoso.com", + "supportUrl": "https://support.contoso.com", + "privacyPolicyUrl": "https://contoso.com/privacy", + "aboutUrl": "https://contoso.com/about" } } } diff --git a/docs/settings/detection-rules.md b/docs/settings/detection-rules.md index 4f3c466..1babb7b 100644 --- a/docs/settings/detection-rules.md +++ b/docs/settings/detection-rules.md @@ -41,6 +41,14 @@ MSPs and IT departments commonly need to exclude phishing training platforms (li Add URLs or patterns that should be excluded from phishing detection. This is useful for internal company sites or trusted third-party services that might trigger false positives. +**Dual Protection:** Your allowlist serves two purposes: +1. **Prevents false positives** - Sites you add won't be flagged as phishing +2. **Domain squatting protection** - Domains extracted from your allowlist are automatically protected against typosquatting and look-alike attacks + +For example, adding `https://yourcompany.com/*` will both allow that site AND protect against fake domains like `yourcompany.net`, `your-company.com`, or `y0urcompany.com`. + +Learn more about [Domain Squatting Detection](../features/domain-squatting-detection.md). + **How it works:** Your allowlist patterns are **added to** (not replacing) the default CyberDrain exclusions, providing additional protection without losing baseline coverage. You can use: diff --git a/enterprise/Check-Extension-Policy.reg b/enterprise/Check-Extension-Policy.reg index fce2f70..3ac0464 100644 --- a/enterprise/Check-Extension-Policy.reg +++ b/enterprise/Check-Extension-Policy.reg @@ -20,11 +20,26 @@ Windows Registry Editor Version 5.00 "updateInterval"=dword:00000018 "enableDebugLogging"=dword:00000000 +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\knepjpocdagponkonnbggpcnhnaikajg\policy\domainSquatting] +"enabled"=dword:00000001 + +; Generic webhook configuration (optional) +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\knepjpocdagponkonnbggpcnhnaikajg\policy\genericWebhook] +"enabled"=dword:00000000 +"url"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\knepjpocdagponkonnbggpcnhnaikajg\policy\genericWebhook\events] +"1"="detection_alert" +"2"="page_blocked" + ; Custom branding configuration [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\3rdparty\extensions\knepjpocdagponkonnbggpcnhnaikajg\policy\customBranding] "companyName"="CyberDrain" "productName"="Check" "supportEmail"="" +"supportUrl"="" +"privacyPolicyUrl"="" +"aboutUrl"="" "primaryColor"="#F77F00" "logoUrl"="" @@ -52,11 +67,26 @@ Windows Registry Editor Version 5.00 "updateInterval"=dword:00000018 "enableDebugLogging"=dword:00000000 +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\benimdeioplgkhanklclahllklceahbe\policy\domainSquatting] +"enabled"=dword:00000001 + +; Generic webhook configuration for Chrome (optional) +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\benimdeioplgkhanklclahllklceahbe\policy\genericWebhook] +"enabled"=dword:00000000 +"url"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\benimdeioplgkhanklclahllklceahbe\policy\genericWebhook\events] +"1"="detection_alert" +"2"="page_blocked" + ; Custom branding configuration for Chrome [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\extensions\benimdeioplgkhanklclahllklceahbe\policy\customBranding] "companyName"="CyberDrain" "productName"="Check" "supportEmail"="" +"supportUrl"="" +"privacyPolicyUrl"="" +"aboutUrl"="" "primaryColor"="#F77F00" "logoUrl"="" diff --git a/enterprise/Deploy-Windows-Chrome-and-Edge.ps1 b/enterprise/Deploy-Windows-Chrome-and-Edge.ps1 index b886eb8..af90153 100644 --- a/enterprise/Deploy-Windows-Chrome-and-Edge.ps1 +++ b/enterprise/Deploy-Windows-Chrome-and-Edge.ps1 @@ -22,6 +22,7 @@ $cippTenantId = "" # This will set the "Tenant ID/Domain" option in the extensio $customRulesUrl = "" # This will set the "Config URL" option in the Detection Configuration settings; default is blank. $updateInterval = 24 # This will set the "Update Interval" option in the Detection Configuration settings; default is 24 (hours). Range: 1-168 hours (1 hour to 1 week). $urlAllowlist = @() # This will set the "URL Allowlist" option in the Detection Configuration settings; default is blank; if you want to add multiple URLs, add them as a comma-separated list within the brackets (e.g., @("https://example1.com", "https://example2.com")). Supports simple URLs with * wildcard (e.g., https://*.example.com) or advanced regex patterns (e.g., ^https:\/\/(www\.)?example\.com\/.*$). +$domainSquattingEnabled = 1 # 0 = Disabled, 1 = Enabled; default is 1; controls domain squatting detection from managed policy/config. $enableDebugLogging = 0 # 0 = Unchecked, 1 = Checked (Enabled); default is 0; This will set the "Enable Debug Logging" option in the Activity Log settings. # Generic Webhook Settings @@ -31,9 +32,11 @@ $webhookEvents = @() # This will set the "Event Types" to send to the webhook; d # Custom Branding Settings $companyName = "CyberDrain" # This will set the "Company Name" option in the Custom Branding settings; default is "CyberDrain". -$companyURL = "https://cyberdrain.com" # This will set the Company URL option in the Custom Branding settings; default is "https://cyberdrain.com"; Must include the protocol (e.g., https://). $productName = "Check - Phishing Protection" # This will set the "Product Name" option in the Custom Branding settings; default is "Check - Phishing Protection". $supportEmail = "" # This will set the "Support Email" option in the Custom Branding settings; default is blank. +$supportUrl = "" # This will set the "Support URL" option in the Custom Branding settings; default is blank. +$privacyPolicyUrl = "" # This will set the "Privacy URL" option in the Custom Branding settings; default is blank. +$aboutUrl = "" # This will set the "About URL" option in the Custom Branding settings; default is blank. $primaryColor = "#F77F00" # This will set the "Primary Color" option in the Custom Branding settings; default is "#F77F00"; must be a valid hex color code (e.g., #FFFFFF). $logoUrl = "" # This will set the "Logo URL" option in the Custom Branding settings; default is blank. Must be a valid URL including the protocol (e.g., https://example.com/logo.png); protocol must be https; recommended size is 48x48 pixels with a maximum of 128x128. @@ -66,6 +69,13 @@ function Configure-ExtensionSettings { New-ItemProperty -Path $ManagedStorageKey -Name "updateInterval" -PropertyType DWord -Value $updateInterval -Force | Out-Null New-ItemProperty -Path $ManagedStorageKey -Name "enableDebugLogging" -PropertyType DWord -Value $enableDebugLogging -Force | Out-Null + # Create and configure domain squatting policy settings + $domainSquattingKey = "$ManagedStorageKey\domainSquatting" + if (!(Test-Path $domainSquattingKey)) { + New-Item -Path $domainSquattingKey -Force | Out-Null + } + New-ItemProperty -Path $domainSquattingKey -Name "enabled" -PropertyType DWord -Value $domainSquattingEnabled -Force | Out-Null + # Create and configure URL allow list $urlAllowlistKey = "$ManagedStorageKey\urlAllowlist" if (!(Test-Path $urlAllowlistKey)) { @@ -90,9 +100,11 @@ function Configure-ExtensionSettings { # Set custom branding settings New-ItemProperty -Path $customBrandingKey -Name "companyName" -PropertyType String -Value $companyName -Force | Out-Null - New-ItemProperty -Path $customBrandingKey -Name "companyURL" -PropertyType String -Value $companyURL -Force | Out-Null New-ItemProperty -Path $customBrandingKey -Name "productName" -PropertyType String -Value $productName -Force | Out-Null New-ItemProperty -Path $customBrandingKey -Name "supportEmail" -PropertyType String -Value $supportEmail -Force | Out-Null + New-ItemProperty -Path $customBrandingKey -Name "supportUrl" -PropertyType String -Value $supportUrl -Force | Out-Null + New-ItemProperty -Path $customBrandingKey -Name "privacyPolicyUrl" -PropertyType String -Value $privacyPolicyUrl -Force | Out-Null + New-ItemProperty -Path $customBrandingKey -Name "aboutUrl" -PropertyType String -Value $aboutUrl -Force | Out-Null New-ItemProperty -Path $customBrandingKey -Name "primaryColor" -PropertyType String -Value $primaryColor -Force | Out-Null New-ItemProperty -Path $customBrandingKey -Name "logoUrl" -PropertyType String -Value $logoUrl -Force | Out-Null @@ -145,4 +157,4 @@ function Configure-ExtensionSettings { # Configure settings for Chrome and Edge Configure-ExtensionSettings -ExtensionId $chromeExtensionId -UpdateUrl $chromeUpdateUrl -ManagedStorageKey $chromeManagedStorageKey -ExtensionSettingsKey $chromeExtensionSettingsKey -Configure-ExtensionSettings -ExtensionId $edgeExtensionId -UpdateUrl $edgeUpdateUrl -ManagedStorageKey $edgeManagedStorageKey -ExtensionSettingsKey $edgeExtensionSettingsKey \ No newline at end of file +Configure-ExtensionSettings -ExtensionId $edgeExtensionId -UpdateUrl $edgeUpdateUrl -ManagedStorageKey $edgeManagedStorageKey -ExtensionSettingsKey $edgeExtensionSettingsKey diff --git a/enterprise/README.md b/enterprise/README.md index 5ec8974..db3e4f1 100644 --- a/enterprise/README.md +++ b/enterprise/README.md @@ -26,8 +26,9 @@ This folder contains enterprise deployment resources for the Check Microsoft 365 ## Quick Links - **Chrome/Edge Deployment**: See `Deploy-Windows-Chrome-and-Edge.ps1` for Windows, `macos-linux/` for macOS/Linux -- **Firefox Deployment**: See `firefox/policies.json` template and [Firefox Deployment Guide](../docs/deployment/firefox-deployment.md) -- **Configuration Schema**: See `../config/managed_schema.json` for all available settings +- **Firefox Deployment**: See `firefox/policies.json` template and [Firefox Deployment Guide](../docs/deployment/firefox-deployment.md) +- **Configuration Schema**: See `../config/managed_schema.json` for all available settings +- **Webhook Configuration**: See `../docs/webhooks.md` for webhook payloads and supported event types ## Security Considerations diff --git a/enterprise/Remove-Windows-Chrome-and-Edge.ps1 b/enterprise/Remove-Windows-Chrome-and-Edge.ps1 index fed3c9d..cad4445 100644 --- a/enterprise/Remove-Windows-Chrome-and-Edge.ps1 +++ b/enterprise/Remove-Windows-Chrome-and-Edge.ps1 @@ -58,14 +58,51 @@ function Remove-ExtensionSettings { } } + # Remove generic webhook subkey and event properties + $genericWebhookKey = "$ManagedStorageKey\genericWebhook" + if (Test-Path $genericWebhookKey) { + $webhookEventsKey = "$genericWebhookKey\events" + if (Test-Path $webhookEventsKey) { + $eventProperties = Get-ItemProperty -Path $webhookEventsKey -ErrorAction SilentlyContinue + if ($eventProperties) { + $eventProperties.PSObject.Properties | Where-Object { $_.Name -match '^\d+$' } | ForEach-Object { + Remove-ItemProperty -Path $webhookEventsKey -Name $_.Name -Force -ErrorAction SilentlyContinue + Write-Host "Removed webhook event property: $($_.Name) from $webhookEventsKey" + } + } + try { + Remove-Item -Path $webhookEventsKey -Force -ErrorAction SilentlyContinue + Write-Host "Removed webhook events subkey: $webhookEventsKey" + } catch { + # Key may not be empty or may have been removed already + } + } + + foreach ($property in @("enabled", "url")) { + if (Get-ItemProperty -Path $genericWebhookKey -Name $property -ErrorAction SilentlyContinue) { + Remove-ItemProperty -Path $genericWebhookKey -Name $property -Force -ErrorAction SilentlyContinue + Write-Host "Removed generic webhook property: $property from $genericWebhookKey" + } + } + + try { + Remove-Item -Path $genericWebhookKey -Force -ErrorAction SilentlyContinue + Write-Host "Removed generic webhook subkey: $genericWebhookKey" + } catch { + # Key may not be empty or may have been removed already + } + } + # Remove custom branding subkey and all its properties $customBrandingKey = "$ManagedStorageKey\customBranding" if (Test-Path $customBrandingKey) { $brandingPropertiesToRemove = @( "companyName", - "companyURL", "productName", "supportEmail", + "supportUrl", + "privacyPolicyUrl", + "aboutUrl", "primaryColor", "logoUrl" ) diff --git a/enterprise/Test-Extension-Policy.ps1 b/enterprise/Test-Extension-Policy.ps1 index 6a07d23..79c60ec 100644 --- a/enterprise/Test-Extension-Policy.ps1 +++ b/enterprise/Test-Extension-Policy.ps1 @@ -23,16 +23,25 @@ $testConfig = @{ enableDebugLogging = 1 } +$testDomainSquatting = @{ + enabled = 1 +} + # Custom branding test values $testBranding = @{ companyName = "Test Company" - companyURL = "https://example.com" productName = "Test Product" supportEmail = "test@example.com" primaryColor = "#FF6B00" logoUrl = "" } +$testGenericWebhook = @{ + enabled = 0 + url = "" + events = @("detection_alert", "page_blocked") +} + function Set-TestPolicies { param([string]$PolicyKey) @@ -46,6 +55,12 @@ function Set-TestPolicies { $type = if ($value -is [int]) { "DWord" } else { "String" } New-ItemProperty -Path $PolicyKey -Name $key -PropertyType $type -Value $value -Force | Out-Null } + + $domainSquattingKey = "$PolicyKey\domainSquatting" + if (!(Test-Path $domainSquattingKey)) { + New-Item -Path $domainSquattingKey -Force | Out-Null + } + New-ItemProperty -Path $domainSquattingKey -Name "enabled" -PropertyType DWord -Value $testDomainSquatting.enabled -Force | Out-Null $brandingKey = "$PolicyKey\customBranding" if (!(Test-Path $brandingKey)) { @@ -55,6 +70,22 @@ function Set-TestPolicies { foreach ($key in $testBranding.Keys) { New-ItemProperty -Path $brandingKey -Name $key -PropertyType String -Value $testBranding[$key] -Force | Out-Null } + + $genericWebhookKey = "$PolicyKey\genericWebhook" + if (!(Test-Path $genericWebhookKey)) { + New-Item -Path $genericWebhookKey -Force | Out-Null + } + New-ItemProperty -Path $genericWebhookKey -Name "enabled" -PropertyType DWord -Value $testGenericWebhook.enabled -Force | Out-Null + New-ItemProperty -Path $genericWebhookKey -Name "url" -PropertyType String -Value $testGenericWebhook.url -Force | Out-Null + + $webhookEventsKey = "$genericWebhookKey\events" + if (!(Test-Path $webhookEventsKey)) { + New-Item -Path $webhookEventsKey -Force | Out-Null + } + Remove-ItemProperty -Path $webhookEventsKey -Name * -Force -ErrorAction SilentlyContinue | Out-Null + for ($i = 0; $i -lt $testGenericWebhook.events.Count; $i++) { + New-ItemProperty -Path $webhookEventsKey -Name ($i + 1) -PropertyType String -Value $testGenericWebhook.events[$i] -Force | Out-Null + } Write-Output "Applied test policies to: $PolicyKey" } @@ -71,6 +102,18 @@ function Show-CurrentPolicies { Write-Output "`nCustom Branding:" Get-ItemProperty -Path $brandingKey | Format-List } + + $genericWebhookKey = "$PolicyKey\genericWebhook" + if (Test-Path $genericWebhookKey) { + Write-Output "`nGeneric Webhook:" + Get-ItemProperty -Path $genericWebhookKey | Format-List + } + + $domainSquattingKey = "$PolicyKey\domainSquatting" + if (Test-Path $domainSquattingKey) { + Write-Output "`nDomain Squatting:" + Get-ItemProperty -Path $domainSquattingKey | Format-List + } } else { Write-Output "No policies set at: $PolicyKey" } diff --git a/enterprise/admx/Check-Extension.admx b/enterprise/admx/Check-Extension.admx index d69c262..2918bd2 100644 --- a/enterprise/admx/Check-Extension.admx +++ b/enterprise/admx/Check-Extension.admx @@ -122,6 +122,36 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -176,6 +206,33 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -206,6 +263,18 @@ + + + + + + + + + + + + @@ -306,6 +375,36 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -360,6 +459,33 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -389,6 +515,18 @@ + + + + + + + + + + + + diff --git a/enterprise/admx/en-US/Check-Extension.adml b/enterprise/admx/en-US/Check-Extension.adml index 078a8c1..af97141 100644 --- a/enterprise/admx/en-US/Check-Extension.adml +++ b/enterprise/admx/en-US/Check-Extension.adml @@ -115,6 +115,36 @@ This helps identify which tenant/organization the security event originated from when using a shared CIPP instance. + + Enable generic webhook + + This policy controls whether the Check extension sends selected security events to a custom webhook endpoint. + + When enabled: Events listed in "Generic webhook event types" are sent to the configured Generic Webhook URL. + When disabled (default): No generic webhook events are sent. + + Note: Requires Generic Webhook URL and at least one event type. + + Generic webhook URL + + This policy specifies the URL for a custom webhook endpoint that receives Check event payloads. + + Example: https://webhook.yourcompany.com/check-events + + This setting is only used when generic webhook is enabled. + + Generic webhook event types + + This policy specifies which event types are sent to the generic webhook endpoint. + + Supported values: + - detection_alert + - false_positive_report + - page_blocked + - rogue_app_detected + - threat_detected + - validation_event + Custom detection rules URL @@ -181,15 +211,6 @@ The company name appears in the extension popup and settings pages. - - Company URL - - This policy specifies the company URL used in the extension for branding and navigation purposes. - - Example: https://contoso.com - - The company URL is used for linking back to the company website from the extension interface. - Product name @@ -208,6 +229,27 @@ This email address is displayed in the extension interface and help documentation. + + Support URL + + This policy specifies the support URL opened by the extension Support link. + + Example: https://support.contoso.com + + + Privacy URL + + This policy specifies the privacy policy URL opened by the extension Privacy link. + + Example: https://contoso.com/privacy + + + About URL + + This policy specifies the about URL opened by the extension About link. + + Example: https://contoso.com/about + Primary theme color @@ -236,6 +278,13 @@ Debug logging should only be enabled for troubleshooting as it may impact performance and generate large log files. + Enable domain squatting detection + + This policy controls domain squatting detection in the Check extension. + + When enabled (default): Typosquatting, homoglyph, and combosquatting protections are active. + When disabled: Domain squatting detections are skipped. + Enable debug logging (Chrome) @@ -246,6 +295,13 @@ Debug logging should only be enabled for troubleshooting as it may impact performance and generate large log files. + Enable domain squatting detection (Chrome) + + This policy controls domain squatting detection in the Check extension for Google Chrome. + + When enabled (default): Typosquatting, homoglyph, and combosquatting protections are active. + When disabled: Domain squatting detections are skipped. + Show valid page badge (Chrome) @@ -300,6 +356,36 @@ This helps identify which tenant/organization the security event originated from when using a shared CIPP instance. + + Enable generic webhook (Chrome) + + This policy controls whether the Check extension sends selected security events to a custom webhook endpoint in Google Chrome. + + When enabled: Events listed in "Generic webhook event types (Chrome)" are sent to the configured Generic Webhook URL. + When disabled (default): No generic webhook events are sent. + + Note: Requires Generic Webhook URL and at least one event type. + + Generic webhook URL (Chrome) + + This policy specifies the URL for a custom webhook endpoint that receives Check event payloads from Google Chrome. + + Example: https://webhook.yourcompany.com/check-events + + This setting is only used when generic webhook is enabled. + + Generic webhook event types (Chrome) + + This policy specifies which event types are sent to the generic webhook endpoint from Google Chrome. + + Supported values: + - detection_alert + - false_positive_report + - page_blocked + - rogue_app_detected + - threat_detected + - validation_event + Custom detection rules URL (Chrome) @@ -330,15 +416,6 @@ The company name appears in the extension popup and settings pages. - - Company URL (Chrome) - - This policy specifies the company URL used in the extension for branding and navigation purposes in Google Chrome. - - Example: https://contoso.com - - The company URL is used for linking back to the company website from the extension interface. - Product name (Chrome) @@ -357,6 +434,27 @@ This email address is displayed in the extension interface and help documentation. + + Support URL (Chrome) + + This policy specifies the support URL opened by the extension Support link in Google Chrome. + + Example: https://support.contoso.com + + + Privacy URL (Chrome) + + This policy specifies the privacy policy URL opened by the extension Privacy link in Google Chrome. + + Example: https://contoso.com/privacy + + + About URL (Chrome) + + This policy specifies the about URL opened by the extension About link in Google Chrome. + + Example: https://contoso.com/about + Primary theme color (Chrome) @@ -387,6 +485,14 @@ + + + + + + + Generic Webhook Event Types: + @@ -409,11 +515,6 @@ - - - - - @@ -424,6 +525,21 @@ + + + + + + + + + + + + + + + @@ -444,6 +560,14 @@ + + + + + + + Generic Webhook Event Types: + @@ -458,11 +582,6 @@ - - - - - @@ -473,6 +592,21 @@ + + + + + + + + + + + + + + + @@ -491,4 +625,4 @@ - \ No newline at end of file + diff --git a/enterprise/firefox/policies.json b/enterprise/firefox/policies.json index be564a9..bb6a250 100644 --- a/enterprise/firefox/policies.json +++ b/enterprise/firefox/policies.json @@ -28,12 +28,17 @@ "customRulesUrl": "https://raw.githubusercontent.com/CyberDrain/Check/refs/heads/main/rules/detection-rules.json", "updateInterval": 24, "urlAllowlist": [], + "domainSquatting": { + "enabled": true + }, "enableDebugLogging": false, "customBranding": { "companyName": "", - "companyURL": "https://cyberdrain.com/", "productName": "", "supportEmail": "", + "supportUrl": "", + "privacyPolicyUrl": "", + "aboutUrl": "", "primaryColor": "#F77F00", "logoUrl": "" }, @@ -50,4 +55,4 @@ } } } -} \ No newline at end of file +} diff --git a/enterprise/macos-linux/README.md b/enterprise/macos-linux/README.md index 8e1d55a..fc9509b 100644 --- a/enterprise/macos-linux/README.md +++ b/enterprise/macos-linux/README.md @@ -158,9 +158,15 @@ All settings are based on the managed schema and include: - **`cippServerUrl`** - CIPP server URL for reporting - **`cippTenantId`** - Tenant identifier for multi-tenant environments +### Generic Webhook Integration +- **`genericWebhook.enabled`** - Enable sending events to custom webhook endpoint +- **`genericWebhook.url`** - Webhook endpoint URL +- **`genericWebhook.events`** - Event types to send (`detection_alert`, `false_positive_report`, `page_blocked`, `rogue_app_detected`, `threat_detected`, `validation_event`) + ### Rule Management - **`customRulesUrl`** - URL for custom detection rules - **`updateInterval`** - Rule update interval in hours (default: 24) +- **`domainSquatting.enabled`** - Enable/disable domain squatting detection (default: true) ### Custom Branding - **`companyName`** - Company name for white labeling @@ -260,10 +266,11 @@ ls -la /etc/microsoft-edge/policies/managed/ Before deployment, edit the JSON files to customize: 1. **CIPP Integration** - Set `cippServerUrl` and `cippTenantId` -2. **Custom Rules** - Set `customRulesUrl` to your rules endpoint -3. **Branding** - Configure company name, colors, and logo URL -4. **Security Settings** - Adjust notification and blocking preferences -5. **Debug Mode** - Enable `enableDebugLogging` for troubleshooting +2. **Webhook Integration** - Configure `genericWebhook.enabled`, `genericWebhook.url`, and `genericWebhook.events` +3. **Custom Rules** - Set `customRulesUrl` to your rules endpoint +4. **Branding** - Configure company name, colors, and logo URL +5. **Security Settings** - Adjust notification and blocking preferences +6. **Debug Mode** - Enable `enableDebugLogging` for troubleshooting ## Security Considerations diff --git a/enterprise/macos-linux/check-extension-config.mobileconfig b/enterprise/macos-linux/check-extension-config.mobileconfig index c3b77bb..e87ff3d 100644 --- a/enterprise/macos-linux/check-extension-config.mobileconfig +++ b/enterprise/macos-linux/check-extension-config.mobileconfig @@ -46,6 +46,18 @@ Value + genericWebhook + + Value + + enabled + + url + + events + + + customRulesUrl Value @@ -56,6 +68,14 @@ Value 24 + domainSquatting + + Value + + enabled + + + enableDebugLogging @@ -102,4 +122,4 @@ TargetDeviceType 5 - \ No newline at end of file + diff --git a/enterprise/macos-linux/chrome-managed-policy.json b/enterprise/macos-linux/chrome-managed-policy.json index 58ac0eb..9890c57 100644 --- a/enterprise/macos-linux/chrome-managed-policy.json +++ b/enterprise/macos-linux/chrome-managed-policy.json @@ -18,10 +18,16 @@ "customRulesUrl": "", "updateInterval": 24, "enableDebugLogging": false, + "domainSquatting": { + "enabled": true + }, "customBranding": { "companyName": "", "productName": "", "supportEmail": "", + "supportUrl": "", + "privacyPolicyUrl": "", + "aboutUrl": "", "primaryColor": "#F77F00", "logoUrl": "" }, @@ -37,4 +43,4 @@ } } } -} \ No newline at end of file +} diff --git a/enterprise/macos-linux/deploy-extension-prefs.sh b/enterprise/macos-linux/deploy-extension-prefs.sh index 65b2b45..2f76344 100644 --- a/enterprise/macos-linux/deploy-extension-prefs.sh +++ b/enterprise/macos-linux/deploy-extension-prefs.sh @@ -71,6 +71,15 @@ create_extension_preferences() { cippTenantId + genericWebhook + + enabled + + url + + events + + customRulesUrl $custom_rules_url updateInterval @@ -211,4 +220,4 @@ main() { esac } -main "$@" \ No newline at end of file +main "$@" diff --git a/enterprise/macos-linux/edge-managed-policy.json b/enterprise/macos-linux/edge-managed-policy.json index fc44bd0..6fe986b 100644 --- a/enterprise/macos-linux/edge-managed-policy.json +++ b/enterprise/macos-linux/edge-managed-policy.json @@ -18,10 +18,16 @@ "customRulesUrl": "", "updateInterval": 24, "enableDebugLogging": false, + "domainSquatting": { + "enabled": true + }, "customBranding": { "companyName": "", "productName": "", "supportEmail": "", + "supportUrl": "", + "privacyPolicyUrl": "", + "aboutUrl": "", "primaryColor": "#F77F00", "logoUrl": "" }, @@ -37,4 +43,4 @@ } } } -} \ No newline at end of file +} diff --git a/manifest.firefox.json b/manifest.firefox.json index e8eb957..d163c20 100644 --- a/manifest.firefox.json +++ b/manifest.firefox.json @@ -1,7 +1,7 @@ { "manifest_version": 3, "name": "Check by CyberDrain", - "version": "1.1.0", + "version": "1.2.0", "description": "Protect against phishing attacks targeting Microsoft 365 login pages with enterprise-grade detection", "permissions": [ "storage", @@ -67,7 +67,10 @@ "browser_specific_settings": { "gecko": { "id": "check@cyberdrain.com", - "strict_min_version": "109.0" + "strict_min_version": "142.0", + "data_collection_permissions": { + "required": ["none"] + } } } } diff --git a/manifest.json b/manifest.json index ca78360..04fe37c 100644 --- a/manifest.json +++ b/manifest.json @@ -1,7 +1,7 @@ { "manifest_version": 3, "name": "Check by CyberDrain", - "version": "1.1.0", + "version": "1.2.0", "description": "Protect against phishing attacks targeting Microsoft 365 login pages with enterprise-grade detection", "permissions": [ "storage", diff --git a/options/options.css b/options/options.css index 5e4ab92..a81a7aa 100644 --- a/options/options.css +++ b/options/options.css @@ -722,6 +722,96 @@ body { letter-spacing: 0.3px; } +/* Collapsible config sections */ +.config-section-collapsible { + margin-bottom: 12px; + border: 1px solid var(--border-color); + border-radius: var(--radius); + overflow: hidden; + background: var(--surface-color); +} + +.config-section-header { + display: flex; + align-items: center; + justify-content: space-between; + padding: 12px 16px; + cursor: pointer; + user-select: none; + background: var(--surface-color); + transition: background-color 0.2s ease; +} + +.config-section-header:hover { + background: var(--background-color); +} + +.config-section-header-title { + font-weight: 600; + color: var(--primary-color); + font-size: 13px; + text-transform: uppercase; + letter-spacing: 0.5px; + display: flex; + align-items: center; + gap: 8px; +} + +.config-section-toggle { + color: var(--text-muted); + font-size: 20px; + transition: transform 0.2s ease; + line-height: 1; + transform: rotate(180deg); +} + +.config-section-collapsible.expanded .config-section-toggle { + transform: rotate(90deg); +} + +.config-section-content { + max-height: 0; + overflow: hidden; + transition: max-height 0.6s ease-out; +} + +.config-section-collapsible.expanded .config-section-content { + max-height: 2000px; /* Large enough for content */ + transition: max-height 0.8s ease-in; +} + +.config-section-body { + padding: 12px 16px; + border-top: 1px solid var(--border-color); +} + +/* Nested collapsible for lists */ +.config-list-toggle { + color: var(--primary-color); + cursor: pointer; + text-decoration: underline; + font-size: 12px; + margin-top: 8px; + display: inline-block; + transition: color 0.2s ease; +} + +.config-list-toggle:hover { + color: var(--primary-hover); +} + +.config-list-expanded { + margin-top: 0; + margin-bottom: 8px; + padding-left: 0; + display: none; + transition: all 0.5s ease; +} + +.config-list-expanded.visible { + display: block; +} + .config-raw-json { white-space: pre-wrap; font-family: 'Monaco', 'Menlo', 'Ubuntu Mono', monospace; diff --git a/options/options.html b/options/options.html index 7a69aea..72f1534 100644 --- a/options/options.html +++ b/options/options.html @@ -169,6 +169,11 @@

Generic Webhook

Rogue App Detected +