Skip to content

Update Emp Imp Payroll Fraud rule to look for SDN in subject as well#4499

Open
missingn0pe wants to merge 1 commit into
mainfrom
missingn0pe.fn.ESC-13317.payroll_fraud_org_display_name
Open

Update Emp Imp Payroll Fraud rule to look for SDN in subject as well#4499
missingn0pe wants to merge 1 commit into
mainfrom
missingn0pe.fn.ESC-13317.payroll_fraud_org_display_name

Conversation

@missingn0pe
Copy link
Copy Markdown
Member

Description

Adding an or statement to look for org display name in the subject line.

Associated samples

- Sample 1
- Sample 2

Associated hunts

- Hunt 1 (Multi-hunt)

Adding an or statement to look for org display name in the subject line.
@missingn0pe missingn0pe requested a review from a team May 18, 2026 17:31
@missingn0pe missingn0pe requested a review from a team as a code owner May 18, 2026 17:31
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label May 18, 2026
github-actions Bot added a commit that referenced this pull request May 18, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 19, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant