Skip to content

Create body_self_sender_bold_pdf_link.yml#4565

Draft
keaton-sublime wants to merge 2 commits into
mainfrom
keaton-sublime.fn.esc-13021.pdf_bold_link
Draft

Create body_self_sender_bold_pdf_link.yml#4565
keaton-sublime wants to merge 2 commits into
mainfrom
keaton-sublime.fn.esc-13021.pdf_bold_link

Conversation

@keaton-sublime
Copy link
Copy Markdown
Member

Description

Detects messages sent from a user to themselves containing bold PDF links where the link text correlates with the subject line or sender domain, potentially indicating a compromised account or social engineering technique.

Related to #4462

Associated samples

Associated hunts

@keaton-sublime keaton-sublime added the in-test-rules PR is in our testing suite to collect telemetry label May 29, 2026
github-actions Bot added a commit that referenced this pull request May 29, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 29, 2026
github-actions Bot added a commit that referenced this pull request May 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant