Skip to content

Update link_credential_phishing_intent_and_other_indicators.yml - #5077

Open
JFarina5 wants to merge 1 commit into
mainfrom
JFarina5.FN.ESC-21221.link.cred.phish.intent
Open

Update link_credential_phishing_intent_and_other_indicators.yml#5077
JFarina5 wants to merge 1 commit into
mainfrom
JFarina5.FN.ESC-21221.link.cred.phish.intent

Conversation

@JFarina5

Copy link
Copy Markdown
Member

Description

Updating rule to include important <word> update in the subject and the 4 of logic, to include tagging samples with the mailbox root domain in the url path, and three, six to eight, character strings separated by / in the path.

Associated samples

Associated hunts

@JFarina5
JFarina5 requested a review from a team August 10, 2026 23:20
@JFarina5
JFarina5 requested a review from a team as a code owner August 10, 2026 23:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant