-
Notifications
You must be signed in to change notification settings - Fork 81
Create suspicious_matching_subject_sender_display_name.yml #3616
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Create suspicious_matching_subject_sender_display_name.yml #3616
Conversation
…ng 32-character alphanumeric string
…ching 32-character alphanumeric string
…ching 32-character alphanumeric string
| @@ -0,0 +1,37 @@ | |||
| name: "Subject and sender display name contain matching 32-character alphanumeric string" | |||
| description: "Detects messages where both the subject line and sender display name contain identical 32-character alphanumeric strings, which may indicate automated generation or coordination between these fields for malicious purposes." | |||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
consider updating the description to include this matches only where with cred_theft intent or containing a unicode Right-To-Left Mark
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated description.
detection-rules/suspicious_matching_subject_sender_display_name.yml
Outdated
Show resolved
Hide resolved
detection-rules/suspicious_matching_subject_sender_display_name.yml
Outdated
Show resolved
Hide resolved
detection-rules/suspicious_matching_subject_sender_display_name.yml
Outdated
Show resolved
Hide resolved
…e.yml Co-authored-by: Brandon Murphy <4827852+zoomequipd@users.noreply.github.com>
…e.yml Co-authored-by: Brandon Murphy <4827852+zoomequipd@users.noreply.github.com>
…ching 32-character alphanumeric string
…tching long alphanumeric string
…tching long alphanumeric string
Description
Detects messages where both the subject line and sender display name contain identical 32-character alphanumeric strings, which may indicate automated generation or coordination between these fields for malicious purposes.
Associated samples
Associated hunts