Skip to content

Conversation

@IndiaAce
Copy link
Member

@IndiaAce IndiaAce commented Jan 5, 2026

Description

From a runner, testing out the creation of a new rule that has an internal org domain from a "no reply" with high cred theft intent and fail auth. I want to see how this does in test rules.

Associated samples

Associated hunts

  • Rules rely on $org_domains list so hunts can be found in the ticket. This should be a low-volume change, but I want to see what test-rules looks like

Screenshot (insights)

@IndiaAce IndiaAce requested a review from a team as a code owner January 5, 2026 20:11
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Jan 5, 2026
github-actions bot added a commit that referenced this pull request Jan 5, 2026
…h authentication failure and no-reply sender
github-actions bot added a commit that referenced this pull request Jan 6, 2026
…with authentication failure and no-reply sender
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant