Skip to content

Commit e0dec5f

Browse files
[PR #3479] modified rule: Brand impersonation: Google Workspace alert notification
1 parent 1b2383e commit e0dec5f

File tree

1 file changed

+8
-2
lines changed

1 file changed

+8
-2
lines changed

detection-rules/3479_impersonation_google_workspace.yml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,13 @@ source: |
2626
)
2727
and headers.auth_summary.dmarc.pass
2828
)
29-
29+
30+
// Negate legitimate Atlassian/Jira notifications that may contain Google Workspace content
31+
and not (
32+
sender.email.domain.root_domain in~ ('atlassian.net', 'atlassian.com')
33+
and headers.auth_summary.dmarc.pass
34+
)
35+
3036
// Negate legitimate Google alerts forwarded through mailing lists
3137
and not (
3238
any(headers.hops,
@@ -131,4 +137,4 @@ detection_methods:
131137
id: "053558a8-ffee-5bd7-a7d6-217f44e571bc"
132138
og_id: "143ffbc4-15ba-535e-b9d6-ab2e2862abe9"
133139
testing_pr: 3479
134-
testing_sha: 27f56b595c2bc6b19c3bc6df3c2dae3de703edd7
140+
testing_sha: 40b00281075e662aff1bfc9e6abc3dba1ad09440

0 commit comments

Comments
 (0)