Skip to content

Conversation

@peterdj45
Copy link
Member

Description

adding additional regex keywords to account for microsoft teams impersonation

also adding logic to override sender profile and explicit domain negations if the sender domain is not valid

Associated samples

@peterdj45 peterdj45 requested a review from a team as a code owner November 7, 2025 01:02
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Nov 7, 2025
@peterdj45 peterdj45 added the review-needed Indicates that a PR is waiting for review label Nov 15, 2025
github-actions bot added a commit that referenced this pull request Nov 17, 2025
aidenmitchell
aidenmitchell previously approved these changes Nov 17, 2025
Copy link
Member

@zoomequipd zoomequipd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

there are many benign matches in telemetry data.

@peterdj45 peterdj45 removed the review-needed Indicates that a PR is waiting for review label Nov 21, 2025
@peterdj45 peterdj45 dismissed aidenmitchell’s stale review November 21, 2025 09:30

looking further into mode likely benign matches

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants