Skip to content

Conversation

@IndiaAce
Copy link
Member

@IndiaAce IndiaAce commented Nov 6, 2025

Description

From a runner. There's an opportunity here to create some detection-in-depth by creating a rule for emails with an attached zip that contain language suggesting "the password for the encrypted file is: ___" sales invoked ADE and put a new rule in their env, and we have the encrypted attachment detection as well but again, the more the merrier.

Associated samples

Associated hunts

@IndiaAce IndiaAce requested a review from a team as a code owner November 6, 2025 21:48
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Nov 6, 2025
github-actions bot added a commit that referenced this pull request Nov 6, 2025
@IndiaAce
Copy link
Member Author

Telemetry is catching all relevant behavior... marking r4r

@IndiaAce IndiaAce added the review-needed Indicates that a PR is waiting for review label Nov 24, 2025
@IndiaAce IndiaAce added this pull request to the merge queue Nov 25, 2025
Merged via the queue into main with commit a42a9d8 Nov 25, 2025
2 checks passed
@IndiaAce IndiaAce deleted the luke_create_encrypted_attachment_with_password_in_body branch November 25, 2025 14:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants