Skip to content

Create body_html_hidden_conversation.yml#4308

Open
D-Bolton wants to merge 4 commits intomainfrom
daniel.fn.ESC-10080.FN--Brand-impersonation-phishing-abusing-ButcherBox-identity
Open

Create body_html_hidden_conversation.yml#4308
D-Bolton wants to merge 4 commits intomainfrom
daniel.fn.ESC-10080.FN--Brand-impersonation-phishing-abusing-ButcherBox-identity

Conversation

@D-Bolton
Copy link
Copy Markdown
Member

@D-Bolton D-Bolton commented Apr 3, 2026

Description

Detects messages instances of email header fields (From, To, Date) and recipient email addresses hidden within the HTML source code that are not visible in the displayed text, potentially indicating thread hijacking or conversation spoofing.

Associated samples

Associated hunts

@D-Bolton D-Bolton marked this pull request as ready for review April 3, 2026 21:27
@D-Bolton D-Bolton requested a review from a team April 3, 2026 21:27
@D-Bolton D-Bolton requested a review from a team as a code owner April 3, 2026 21:27
github-actions bot added a commit that referenced this pull request Apr 3, 2026
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Apr 3, 2026
github-actions bot added a commit that referenced this pull request Apr 3, 2026
github-actions bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant