Skip to content

Conversation

@IndiaAce
Copy link
Member

@IndiaAce IndiaAce commented Jan 6, 2026

Description

Creating a rule that identifies attachments that contain VIP users in the ocr.text and contain a sender mismatch with high cred theft.

Associated samples

Associated hunts

  • Several hunts can be found in the escalation.

@IndiaAce IndiaAce requested a review from a team as a code owner January 6, 2026 15:23
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Jan 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant