Skip to content

Commit eda4539

Browse files
[PR #3487] modified rule: Brand impersonation: Greenvelope
1 parent 953e8a5 commit eda4539

File tree

1 file changed

+8
-1
lines changed

1 file changed

+8
-1
lines changed

detection-rules/3487_brand_impersonation_greenvelope.yml

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,6 +46,13 @@ source: |
4646
)
4747
)
4848
49+
// avoid fwd/replies
50+
and not (
51+
(subject.is_forward or subject.is_reply)
52+
and (length(headers.references) != 0 or headers.in_reply_to is not null)
53+
and length(body.previous_threads) > 0
54+
)
55+
4956
// Capping length to limit FP's
5057
and length(body.current_thread.text) < 1500
5158
attack_types:
@@ -59,4 +66,4 @@ detection_methods:
5966
id: "07bf6342-6504-5dc2-b2d7-9a84556fd9d5"
6067
og_id: "9cbbf9b8-a44a-5d86-8caa-3aef898841c1"
6168
testing_pr: 3487
62-
testing_sha: 3d5f974244663df2dfc5f9bf6a2d6c76f5204ef5
69+
testing_sha: f690e7e062cc3b76d4d1abd3fb8725d0ee534e0b

0 commit comments

Comments
 (0)