Skip to content

Create credential_theft_new_domain.yml#4311

Closed
cybher0808 wants to merge 2 commits intomainfrom
cybher0808.fn.esc-10040.credtheft
Closed

Create credential_theft_new_domain.yml#4311
cybher0808 wants to merge 2 commits intomainfrom
cybher0808.fn.esc-10040.credtheft

Conversation

@cybher0808
Copy link
Copy Markdown
Member

@cybher0808 cybher0808 commented Apr 3, 2026

Description

Requested from a runner ping - created to find messages containing links to newly registered domains that exhibit credential theft characteristics.

Associated samples

Associated hunts

@cybher0808 cybher0808 requested a review from a team April 3, 2026 23:36
@cybher0808 cybher0808 requested a review from a team as a code owner April 3, 2026 23:36
@cybher0808 cybher0808 changed the title credential_theft_new_domain.yml Create credential_theft_new_domain.yml Apr 3, 2026
@cybher0808 cybher0808 self-assigned this Apr 3, 2026
@cybher0808 cybher0808 added the in-test-rules PR is in our testing suite to collect telemetry label Apr 3, 2026
github-actions bot added a commit that referenced this pull request Apr 3, 2026
…heft with new domain and suspicious indicators
github-actions bot added a commit that referenced this pull request Apr 3, 2026
github-actions bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 8, 2026
…theft with new domain and suspicious indicators
@cybher0808
Copy link
Copy Markdown
Member Author

This rule is not the best example, closing this rule for this sample and other sample.
Noting: The sample mentioned in this PR has coverage.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant