Skip to content

Conversation

@MSAdministrator
Copy link
Member

Description

A new ASR rule that detects messages that reference VIP names or email addresses in quoted message format without being actual replies, potentially indicating impersonation through fabricated conversation threads.

Associated samples

  • see escalation

Associated hunts

  • Hunt 1

@MSAdministrator MSAdministrator self-assigned this Dec 17, 2025
@MSAdministrator MSAdministrator requested a review from a team as a code owner December 17, 2025 15:41
@MSAdministrator MSAdministrator added the in-test-rules PR is in our testing suite to collect telemetry label Dec 17, 2025
@MSAdministrator
Copy link
Member Author

closing as duplicate of #3678

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant