Skip to content

Create link_base64_recipient_with_arrow.yml#4551

Open
D-Bolton wants to merge 2 commits into
mainfrom
daniel.fn.ESC-13980.FN--Spear-phishing
Open

Create link_base64_recipient_with_arrow.yml#4551
D-Bolton wants to merge 2 commits into
mainfrom
daniel.fn.ESC-13980.FN--Spear-phishing

Conversation

@D-Bolton
Copy link
Copy Markdown
Member

@D-Bolton D-Bolton commented May 27, 2026

Description

Detects messages containing links with arrow symbols in the display text where the recipient's email address is base64 encoded within the URL path.

Associated samples

Associated hunts

github-actions Bot added a commit that referenced this pull request May 27, 2026
…ed recipient address in URL with arrow indicator
@D-Bolton D-Bolton marked this pull request as ready for review May 27, 2026 20:14
@D-Bolton D-Bolton requested a review from a team May 27, 2026 20:14
@D-Bolton D-Bolton requested a review from a team as a code owner May 27, 2026 20:14
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label May 27, 2026
github-actions Bot added a commit that referenced this pull request May 27, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 27, 2026
…ded recipient address in URL with arrow indicator
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant