Skip to content

Commit ce3ab2e

Browse files
[PR #3408] modified rule: Brand Impersonation: SAP Concur
1 parent 46493fc commit ce3ab2e

File tree

1 file changed

+15
-6
lines changed

1 file changed

+15
-6
lines changed

detection-rules/3408_brand_impersonation_concur.yml

Lines changed: 15 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -11,16 +11,25 @@ source: |
1111
and (
1212
// Sender display name or domain contains Concur
1313
regex.icontains(sender.display_name, '\bconcur\b')
14-
or strings.ilevenshtein(strings.replace_confusables(sender.display_name),
15-
'concur'
16-
) <= 2
14+
or (
15+
strings.ilevenshtein(strings.replace_confusables(sender.display_name),
16+
'concur'
17+
) <= 2
18+
and not sender.display_name =~ "connor"
19+
)
1720
or strings.icontains(sender.email.domain.domain, 'concur')
1821
or strings.ilevenshtein(sender.email.domain.sld, 'concur') <= 2
22+
// Or spoofing concursolutions.com but failing auth
1923
)
20-
24+
2125
// Not from legitimate Concur domain with valid auth
2226
and not (
23-
sender.email.domain.root_domain in~ ('concursolutions.com', 'concur.com', 'sap.com', 'concurcdc.cn')
27+
sender.email.domain.root_domain in~ (
28+
'concursolutions.com',
29+
'concur.com',
30+
'sap.com',
31+
'concurcdc.cn'
32+
)
2433
and headers.auth_summary.dmarc.pass
2534
)
2635
@@ -38,4 +47,4 @@ detection_methods:
3847
id: "14785ff4-f4bf-583e-a280-81c0075cdb2e"
3948
og_id: "b1e6ebd8-3097-5adb-8d9e-c0e51e7baa95"
4049
testing_pr: 3408
41-
testing_sha: a050d83d1fcccc3270963616554e5115813e6397
50+
testing_sha: 0c2f77afbd531f9127ac824f266abb9dd62a57d1

0 commit comments

Comments
 (0)