Skip to content

Conversation

@MSAdministrator
Copy link
Member

Description

Detects messages from domains containing hyphens and security-related terms like 'noreply', 'notification', or 'secure' with short domain names, commonly used in typosquatting attacks.

Associated samples

  • See escalation

Associated hunts

@MSAdministrator MSAdministrator requested a review from a team as a code owner December 17, 2025 18:34
@MSAdministrator MSAdministrator self-assigned this Dec 17, 2025
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Dec 17, 2025
github-actions bot added a commit that referenced this pull request Dec 17, 2025
@MSAdministrator MSAdministrator added review-needed Indicates that a PR is waiting for review hunting-required Hunts needed to validate rule efficacy and removed review-needed Indicates that a PR is waiting for review hunting-required Hunts needed to validate rule efficacy labels Dec 17, 2025
github-actions bot added a commit that referenced this pull request Dec 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant