Skip to content

Add detection rule for suspicious PDF links in RFQ/RFP#4563

Open
peterdj45 wants to merge 2 commits into
mainfrom
peter.new.link_suspicious_rfq
Open

Add detection rule for suspicious PDF links in RFQ/RFP#4563
peterdj45 wants to merge 2 commits into
mainfrom
peter.new.link_suspicious_rfq

Conversation

@peterdj45
Copy link
Copy Markdown
Member

Description

This rule detects messages with reply or forward subjects that contain links appearing as PDF files but redirect to potentially malicious domains, specifically targeting RFQ or RFP terminology.

Associated samples

Associated hunts

This rule detects messages with reply or forward subjects that contain links appearing as PDF files but redirect to potentially malicious domains, specifically targeting RFQ or RFP terminology.
@peterdj45 peterdj45 requested a review from a team May 28, 2026 22:54
@peterdj45 peterdj45 requested a review from a team as a code owner May 28, 2026 22:54
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label May 28, 2026
github-actions Bot added a commit that referenced this pull request May 28, 2026
github-actions Bot added a commit that referenced this pull request May 28, 2026
…picious Request for Quote or Purchase (RFQ|RFP)
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 28, 2026
…spicious Request for Quote or Purchase (RFQ|RFP)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant