Skip to content

Create body_self_sender_bold.yml#4462

Open
keaton-sublime wants to merge 8 commits into
mainfrom
keaton-sublime.fn.esc-13021.plaza_bold
Open

Create body_self_sender_bold.yml#4462
keaton-sublime wants to merge 8 commits into
mainfrom
keaton-sublime.fn.esc-13021.plaza_bold

Conversation

@keaton-sublime
Copy link
Copy Markdown
Member

Description

Detects messages where the sender's email address matches the recipient's email address, with the sender's display name appearing in bold text and a suspicious 'Read the Message' link present in the body.
Observed in a few campaigns with this type of behavior.

Associated samples

Associated hunts

@keaton-sublime keaton-sublime added the in-test-rules PR is in our testing suite to collect telemetry label May 7, 2026
github-actions Bot added a commit that referenced this pull request May 7, 2026
…s recipient with bolded name and suspicious link
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 7, 2026
…n: Sender matches recipient with bolded name and suspicious link
github-actions Bot added a commit that referenced this pull request May 7, 2026
…: Sender matches recipient with bolded name and suspicious link
@keaton-sublime
Copy link
Copy Markdown
Member Author

No hits over the last several days in test rules data.
Most recent hunt looks solid: https://platform.sublime.security/messages/hunt?huntId=019e1754-dadc-7215-98ee-1f8d07c28dc6

Marking as ready for review/review-needed.

@keaton-sublime keaton-sublime added the review-needed Indicates that a PR is waiting for review label May 11, 2026
@keaton-sublime keaton-sublime marked this pull request as ready for review May 11, 2026 14:01
@keaton-sublime keaton-sublime requested a review from a team May 11, 2026 14:01
@keaton-sublime keaton-sublime requested a review from a team as a code owner May 11, 2026 14:01
@zoomequipd zoomequipd self-requested a review May 14, 2026 21:41
Comment thread detection-rules/body_self_sender_bold.yml Outdated
github-actions Bot added a commit that referenced this pull request May 15, 2026
…ches recipient with bolded name and suspicious link
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 15, 2026
…tion: Sender matches recipient with bolded name and suspicious link
github-actions Bot added a commit that referenced this pull request May 15, 2026
…ion: Sender matches recipient with bolded name and suspicious link
@keaton-sublime
Copy link
Copy Markdown
Member Author

Last 14d test rules data looks pretty good, and all FPs are correctly identified by ASA

@keaton-sublime keaton-sublime requested a review from zoomequipd May 26, 2026 12:27
@keaton-sublime keaton-sublime enabled auto-merge May 26, 2026 18:48
@keaton-sublime keaton-sublime disabled auto-merge May 26, 2026 18:48
@zoomequipd zoomequipd self-assigned this May 27, 2026
@zoomequipd
Copy link
Copy Markdown
Member

Continuing to work with @keaton-sublime on this rule

@keaton-sublime keaton-sublime removed the review-needed Indicates that a PR is waiting for review label May 29, 2026
@keaton-sublime
Copy link
Copy Markdown
Member Author

keaton-sublime commented May 29, 2026

Changed some of the rule logic to be a bit narrower:

Hunt
Multi-hunt

I'm also going to do another PR for a wider rule that is looking for more of the generic stuff we miss by filtering this one down.

related hunt: #4565

github-actions Bot added a commit that referenced this pull request May 29, 2026
…ion: Sender matches recipient with bolded name and suspicious link
github-actions Bot added a commit that referenced this pull request May 29, 2026
…ches recipient with bolded name and suspicious link
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 29, 2026
…tion: Sender matches recipient with bolded name and suspicious link
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants