Skip to content

Create link_self_sender_cred_theft_sus_tlds.yml#4507

Open
MSAdministrator wants to merge 3 commits into
mainfrom
msadministrator.fp.ESC-13746.link_self_sender_cred_theft_sus_tlds
Open

Create link_self_sender_cred_theft_sus_tlds.yml#4507
MSAdministrator wants to merge 3 commits into
mainfrom
msadministrator.fp.ESC-13746.link_self_sender_cred_theft_sus_tlds

Conversation

@MSAdministrator
Copy link
Copy Markdown
Member

Related to escalation and is related to multiple candidate rules for this sample.

Description

Detects messages where the sender and recipient are the same, DMARC authentication passes, but the message contains links to suspicious top-level domains and shows machine learning indicators of credential theft intent.

This requires that .pe is added to $suspicious_tlds static-files list.

Associated samples

Associated hunts

Related to escalation and is related to multiple candidate rules for this sample.
@MSAdministrator MSAdministrator self-assigned this May 19, 2026
@MSAdministrator MSAdministrator requested a review from a team May 19, 2026 20:19
@MSAdministrator MSAdministrator requested a review from a team as a code owner May 19, 2026 20:19
@MSAdministrator MSAdministrator added the in-test-rules PR is in our testing suite to collect telemetry label May 19, 2026
github-actions Bot added a commit that referenced this pull request May 19, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 19, 2026
github-actions Bot added a commit that referenced this pull request May 19, 2026
@MSAdministrator
Copy link
Copy Markdown
Member Author

Related to sublime-security/static-files#828

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant