Create self_sender_display_name_email_in_subject.yml#4285
Conversation
…mail and display name in subject
|
This rule is ready. @peterdj45 will review mode results on Monday. |
…h email and display name in subject
…play name in subject
…email and display name in subject
peterdj45
left a comment
There was a problem hiding this comment.
Found some FPs in test rules, primarily messages sent via Hearsay Social (social media marketing platform). Example: https://platform.sublime.security/messages/50471e1a18de024481af14a3b2e7f8c8fe9fff30c14456f355e24c6d3234ae4c
Could maybe negate these via presence of X-HearsaySocial headers? or the message ID, which is hearsaysystems.com. Happy to jam on this if you'd like!
Co-authored-by: Peter Djordjevic <116412909+peterdj45@users.noreply.github.com>
…play name in subject
…th email and display name in subject
…h email and display name in subject
…rench copy/paste instructions and suspicious domains
…e instructions and suspicious domains
…French copy/paste instructions and suspicious domains
I tightened the rule up more. I have multi-hunts in the ESC. Let me know what you think. Thanks! |
peterdj45
left a comment
There was a problem hiding this comment.
LGTM! left you some non-blocking feedback
…icious_domains.yml Co-authored-by: Peter Djordjevic <116412909+peterdj45@users.noreply.github.com>
…icious_domains.yml Co-authored-by: Peter Djordjevic <116412909+peterdj45@users.noreply.github.com>
…icious_domains.yml Co-authored-by: Peter Djordjevic <116412909+peterdj45@users.noreply.github.com>
…structions and suspicious domains (French/Français)
…h copy/paste instructions and suspicious domains (French/Français)
IndiaAce
left a comment
There was a problem hiding this comment.
Approved with non-blocking feedback.
…h copy/paste instructions and suspicious domains (French/Français)
…structions and suspicious domains (French/Français)
Description
Detects messages where the sender emails themselves with both their email address and display name present in the subject line, while the email address differs from the display name.
Associated samples
Associated hunts