Skip to content

New rule: Startup investment solicitation with suspicious indicators#4013

Open
missingn0pe wants to merge 11 commits intomainfrom
missingn0pe-investment-fraud-1-1
Open

New rule: Startup investment solicitation with suspicious indicators#4013
missingn0pe wants to merge 11 commits intomainfrom
missingn0pe-investment-fraud-1-1

Conversation

@missingn0pe
Copy link
Copy Markdown
Member

Description

This rule detects investment fraud messages related to startups by identifying specific keywords and suspicious indicators in the sender's email and message content.

Associated samples

- Sample 1
- Sample 2
- Sample 3

Associated hunts

- Hunt 1

…icious indicators

This rule detects investment fraud messages related to startups by identifying specific keywords and suspicious indicators in the sender's email and message content.
@missingn0pe missingn0pe requested a review from a team February 12, 2026 15:38
@missingn0pe missingn0pe requested a review from a team as a code owner February 12, 2026 15:38
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Feb 12, 2026
github-actions Bot added a commit that referenced this pull request Feb 12, 2026
github-actions Bot added a commit that referenced this pull request Feb 12, 2026
github-actions Bot added a commit that referenced this pull request Feb 17, 2026
…d: Startup investment solicitation with suspicious indicators
github-actions Bot added a commit that referenced this pull request Feb 17, 2026
…stment solicitation with suspicious indicators
Added subject.is negation
github-actions Bot added a commit that referenced this pull request Feb 18, 2026
…d: Startup investment solicitation with suspicious indicators
Limits FP's on investor outreach for POC help.
github-actions Bot added a commit that referenced this pull request Feb 18, 2026
…stment solicitation with suspicious indicators
github-actions Bot added a commit that referenced this pull request Feb 18, 2026
…stment solicitation with suspicious indicators
github-actions Bot added a commit that referenced this pull request Feb 18, 2026
…d: Startup investment solicitation with suspicious indicators
Removed 'VC' from money keywords and added new, more targeted, keywords instead. Added 2 negations typically only seen with legitimate investor relations & investor pitches.
github-actions Bot added a commit that referenced this pull request Feb 19, 2026
…stment solicitation with suspicious indicators
github-actions Bot added a commit that referenced this pull request Feb 19, 2026
…d: Startup investment solicitation with suspicious indicators
Negating topics & keywords for irrelevant FP's
github-actions Bot added a commit that referenced this pull request Mar 2, 2026
…stment solicitation with suspicious indicators
github-actions Bot added a commit that referenced this pull request Mar 2, 2026
…d: Startup investment solicitation with suspicious indicators
github-actions Bot added a commit that referenced this pull request Mar 2, 2026
…d: Startup investment solicitation with suspicious indicators
github-actions Bot added a commit that referenced this pull request Mar 2, 2026
…stment solicitation with suspicious indicators
Accounting for verbiage variable on FP's.
github-actions Bot added a commit that referenced this pull request Mar 3, 2026
…d: Startup investment solicitation with suspicious indicators
github-actions Bot added a commit that referenced this pull request Mar 3, 2026
…stment solicitation with suspicious indicators
@missingn0pe
Copy link
Copy Markdown
Member Author

Low FP rate on benign messages. Possibly needs to be as ASR rule. Largest FP vector is sales pitches targeting start-ups and loose unsubscribe phrasing.

@missingn0pe missingn0pe added the review-needed Indicates that a PR is waiting for review label Mar 4, 2026
Reducing severity of rule name for broader scope
github-actions Bot added a commit that referenced this pull request Mar 6, 2026
github-actions Bot added a commit that referenced this pull request Mar 6, 2026
…nvestment solicitation with suspicious indicators
@IndiaAce
Copy link
Copy Markdown
Member

Hey @missingn0pe! Let's review this live together!

@IndiaAce IndiaAce removed the review-needed Indicates that a PR is waiting for review label Mar 16, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 8, 2026
…estment solicitation with suspicious indicators
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants