Skip to content

Commit ba5f6d3

Browse files
Update attachment_ics_meeting_invite.yml
1 parent a1be97c commit ba5f6d3

File tree

1 file changed

+2
-8
lines changed

1 file changed

+2
-8
lines changed

detection-rules/attachment_ics_meeting_invite.yml

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -9,14 +9,8 @@ source: |
99
.file_extension in~ ('ics')
1010
or .content_type in ("application/ics", "text/calendar")
1111
),
12-
(
13-
regex.contains(.file_name, "meeting_[a-zA-Z]{5}")
14-
or regex.contains(.file_name, "meeting_[a-zA-Z0-9]{5}")
15-
)
16-
and not (
17-
regex.contains(.file_name, "meeting_invit[eation]")
18-
or regex.contains(.file_name, "meeting_request")
19-
)
12+
regex.icontains(.file_name, 'meeting_[a-zA-Z0-9]{5}\.')
13+
and not strings.contains(.file_name, "meeting_invite")
2014
)
2115
attack_types:
2216
- "BEC/Fraud"

0 commit comments

Comments
 (0)