Skip to content

Create link_self_sender_cred_theft_config_placeholder.yml#4503

Open
D-Bolton wants to merge 2 commits into
mainfrom
daniel.FN.ESC-13727.sharepoint-cred-phish
Open

Create link_self_sender_cred_theft_config_placeholder.yml#4503
D-Bolton wants to merge 2 commits into
mainfrom
daniel.FN.ESC-13727.sharepoint-cred-phish

Conversation

@D-Bolton
Copy link
Copy Markdown
Member

@D-Bolton D-Bolton commented May 18, 2026

Description

Detects messages where the sender and recipient are the same address, containing credential theft language and links with configuration placeholder text indicating a phishing lure.

Associated samples

Associated hunts

github-actions Bot added a commit that referenced this pull request May 18, 2026
…credential theft with configuration placeholder
@D-Bolton D-Bolton marked this pull request as ready for review May 18, 2026 22:12
@D-Bolton D-Bolton requested a review from a team May 18, 2026 22:12
@D-Bolton D-Bolton requested a review from a team as a code owner May 18, 2026 22:12
@github-actions github-actions Bot added test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules hunting-required Hunts needed to validate rule efficacy labels May 18, 2026
@github-actions
Copy link
Copy Markdown
Contributor

Test Rules Sync - Excluded

This PR contains rules that use ml.link_analysis, which is not supported in the test-rules environment.

The hunting-required label has been applied. These rules will need to be tested through alternative methods.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hunting-required Hunts needed to validate rule efficacy test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant