Skip to content

Commit 8f863fb

Browse files
[PR #4] added rule: Test Draft Rule - Suspicious Attachment
1 parent dd1ae86 commit 8f863fb

File tree

1 file changed

+23
-0
lines changed

1 file changed

+23
-0
lines changed
Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
name: "Test Draft Rule - Suspicious Attachment"
2+
description: "Test rule for draft PR functionality - detects suspicious attachment patterns"
3+
type: "rule"
4+
severity: "medium"
5+
authors:
6+
- github.com/aidenmitchell
7+
source: |
8+
type.inbound
9+
and any(attachments,
10+
.file_extension in~ ("exe", "scr", "bat", "cmd")
11+
and .file_type == "unknown"
12+
)
13+
tags:
14+
- "Attack surface reduction"
15+
attack_types:
16+
- "Malware/Ransomware"
17+
tactics_and_techniques:
18+
- "T1204"
19+
detection_methods:
20+
- "File analysis"
21+
id: "89c3c2fa-c857-5d1e-8d1d-9fe166b7bc6d"
22+
testing_pr: 4
23+
testing_sha: 4e494dd69fc1f048257840f3b2c25acf4890d6f8

0 commit comments

Comments
 (0)