Skip to content

Commit dfc0109

Browse files
Enhance detection rules for credential phishing (#3611)
Co-authored-by: Brandon Murphy <[email protected]>
1 parent cc13a52 commit dfc0109

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

detection-rules/credential_phishing_generic_document_sharing.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ source: |
1212
and (
1313
// subject contains document sharing language
1414
regex.icontains(subject.base,
15-
'\b(has\s+sent\s+you|sent\s+you|shared\s+with\s+you|document\s+to\s+review|document\s*(number|num|#)|file\s+to\s+review|proposal\s+document|new\s+document|document\s+.{0,20}assigned|(complete|review|shared?).{0,20}agreement.{0,20})\b'
15+
'\b(has\s+sent\s+you|sent\s+you|shared\s+with\s+you|document\s+to\s+review|document\s*(number|num|#)|file\s+to\s+review|proposal\s+document|new\s+document|document\s+.{0,20}assigned|(complete|review|shared?).{0,20}agreement.{0,20}|document\s+(?:transfer|shared))\b'
1616
)
1717
or strings.icontains(subject.subject, 'document to review')
1818
or strings.icontains(subject.subject, 'file to review')
@@ -109,6 +109,9 @@ source: |
109109
length(ml.link_analysis(., mode="aggressive").redirect_history) > 0
110110
and ml.link_analysis(., mode="aggressive").effective_url.domain.root_domain in $tranco_10k
111111
)
112+
// or common email marketing/tracking patterns
113+
or regex.match(.href_url.url, 'url\d+\..*\.com/ls/click')
114+
or regex.match(.href_url.path, '/ls/click|/click|/c/')
112115
)
113116
// negate highly trusted sender domains unless they fail DMARC authentication
114117
and (

0 commit comments

Comments
 (0)