You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
name: "Evasion: Hidden Unicode characters with suspicious indicators"
2
+
description: "Detects messages containing excessive hidden Unicode characters (invisible text formatting characters) in the subject line, body, or attachments, combined with suspicious patterns such as lengthy recipient lists, financial/security-related keywords, or specific attachment types commonly abused for evasion."
3
+
type: "rule"
4
+
severity: "medium"
5
+
source: |
6
+
type.inbound
7
+
and not subject.is_reply
8
+
and not sender.email.domain.root_domain in ("github.com")
0 commit comments