-
Notifications
You must be signed in to change notification settings - Fork 86
Create attachment_pdf_file_banking_payment_from_freemail.yml #3661
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Create attachment_pdf_file_banking_payment_from_freemail.yml #3661
Conversation
…ences from freemail sender
|
I'm seeing a lot of telemetry in test rules that is marked likely benign here, I'm unable to load the sample sets to SWS but I think this might need some revision. I'm going to remove the |
…ferences from freemail sender
…ferences from freemail sender
detection-rules/attachment_pdf_file_banking_payment_from_freemail.yml
Outdated
Show resolved
Hide resolved
detection-rules/attachment_pdf_file_banking_payment_from_freemail.yml
Outdated
Show resolved
Hide resolved
detection-rules/attachment_pdf_file_banking_payment_from_freemail.yml
Outdated
Show resolved
Hide resolved
detection-rules/attachment_pdf_file_banking_payment_from_freemail.yml
Outdated
Show resolved
Hide resolved
detection-rules/attachment_pdf_file_banking_payment_from_freemail.yml
Outdated
Show resolved
Hide resolved
|
beyond the suggested changes, where are mostly syntax based, the rule appears to match on a bunch of benign samples. going to remove the |
…ferences from freemail sender
detection-rules/attachment_pdf_file_banking_payment_from_freemail.yml
Outdated
Show resolved
Hide resolved
…ferences from freemail sender
|
Mode results look good |
detection-rules/attachment_pdf_file_banking_payment_from_freemail.yml
Outdated
Show resolved
Hide resolved
detection-rules/attachment_pdf_file_banking_payment_from_freemail.yml
Outdated
Show resolved
Hide resolved
IndiaAce
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
one very small nit and something I noticed with your regex... other than that I think this looks good to me!
…ferences from freemail sender
|
I'm curious if the regex change is going to have larger impact, I'm going to remove r4r until we get some telemetry in test-ruels |
| ) | ||
| // or any defined org brands like: first.last.sublime@freemail | ||
| or any($org_slds, strings.icontains(sender.email.local_part, .)) | ||
| or any($org_brand_names, strings.icontains(sender.email.local_part, .)) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
idk the intention of org_brand_names would be common here.
I"m thinking of things like my company org_sld is tcitruck but my entry in org_brand_names is Traffic Consultants Inc
detection-rules/attachment_pdf_file_banking_payment_from_freemail.yml
Outdated
Show resolved
Hide resolved
…h banking and payment references from freemail sender
…nd payment references from freemail sender
…h banking and payment references from freemail sender
…nd payment references from freemail sender
…with banking and payment references from freemail sender
…g and payment references from freemail sender
…ferences from freemail sender
|
I'm closing this one in favor of this newer rule #3809 |
Description
Adding a new rule for coverage of PDFs used for banking/transfer from a freemail provider.
Detects PDF attachments containing banking terminology such as SWIFT codes, account numbers, and payment references from free email providers. These attachments often contain fraudulent payment instructions or fake banking documents used in business email compromise attacks.
Associated samples
Associated hunts