Skip to content

Commit fb1d85a

Browse files
[PR #3457] modified rule: Brand impersonation: Paperless Post
1 parent dd16382 commit fb1d85a

File tree

1 file changed

+5
-3
lines changed

1 file changed

+5
-3
lines changed

detection-rules/3457_brand_impersonation_paperlesspost.yml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,10 @@ source: |
2020
) < 2
2121
and not (
2222
(subject.is_forward or subject.is_reply)
23-
and (length(headers.references) != 0 or headers.in_reply_to is not null)
24-
and length(body.previous_threads) > 0
23+
and (
24+
(length(headers.references) != 0 or headers.in_reply_to is not null)
25+
or length(body.previous_threads) > 0
26+
)
2527
)
2628
and not (
2729
sender.email.domain.root_domain == "paperlesspost.com"
@@ -41,4 +43,4 @@ detection_methods:
4143
id: "bc42e605-e209-565f-aa99-de14bf398910"
4244
og_id: "e9ec5e09-e50f-5d02-ad14-35a1a1442960"
4345
testing_pr: 3457
44-
testing_sha: 781e64c32d8a4795ef65255b70858f7b5e817af9
46+
testing_sha: 5c998d9cd2864b47845d0149fcb99e46c5c57824

0 commit comments

Comments
 (0)