Skip to content

Create brand_impersonation_mcafee.yml#4125

Merged
IndiaAce merged 6 commits intomainfrom
markmsublime.FN.ESC-7545.mcafee_impersonation
Mar 11, 2026
Merged

Create brand_impersonation_mcafee.yml#4125
IndiaAce merged 6 commits intomainfrom
markmsublime.FN.ESC-7545.mcafee_impersonation

Conversation

@markmsublime
Copy link
Copy Markdown
Member

@markmsublime markmsublime commented Mar 5, 2026

Description

Detects messages impersonating McAfee through display name, subject line, body content, or NLU entity detection when the sender is not from verified McAfee domains or other high-trust domains with valid DMARC authentication.

Associated samples

Associated hunts

@markmsublime markmsublime requested a review from a team March 5, 2026 17:31
@markmsublime markmsublime requested a review from a team as a code owner March 5, 2026 17:31
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Mar 5, 2026
github-actions Bot added a commit that referenced this pull request Mar 5, 2026
github-actions Bot added a commit that referenced this pull request Mar 11, 2026
@markmsublime markmsublime added the review-needed Indicates that a PR is waiting for review label Mar 11, 2026
@markmsublime
Copy link
Copy Markdown
Member Author

telemetry is really good, small amount of FPs worth accepting for large amount of coverage this is providing. Marking ready for review

@IndiaAce IndiaAce added this pull request to the merge queue Mar 11, 2026
Merged via the queue into main with commit 34f67a5 Mar 11, 2026
3 checks passed
@IndiaAce IndiaAce deleted the markmsublime.FN.ESC-7545.mcafee_impersonation branch March 11, 2026 16:25
github-actions Bot added a commit that referenced this pull request Mar 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants