Skip to content

Conversation

@MSAdministrator
Copy link
Member

@MSAdministrator MSAdministrator commented Dec 16, 2025

Description

This is an ADE created rule with modifications.

This rule detect links that display as PDF files but actually point to HTML pages on low-reputation domains, combined with business proposal or document-related social engineering language in the subject or body from external senders.

Originally, this sample was similar to the RFP rule but cause too many FPs with use of previous_threads so closing that one and going with this.

Associated samples

Associated hunts

@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Dec 16, 2025
github-actions bot added a commit that referenced this pull request Dec 16, 2025
@MSAdministrator MSAdministrator added the review-needed Indicates that a PR is waiting for review label Dec 23, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant