Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New rule: VIP local_part impersonation from unsolicited sender #2140

Merged
merged 12 commits into from
Nov 20, 2024

Conversation

morriscode
Copy link
Member

Description

This rule identifies potential impersonation attempts involving the local part of an $org_vip email address. Specifically, it checks for cases where the local part of an $org_vip email (e.g., [email protected]) appears with a different domain (e.g., [email protected]). Additionally, the rule flags emails that match an $org_vip address exactly but fail authentication.

@morriscode morriscode requested a review from a team as a code owner November 20, 2024 05:52
@morriscode
Copy link
Member Author

/update-test-rules

github-actions bot pushed a commit that referenced this pull request Nov 20, 2024
Create vip_impersonation_local_or_spoof.yml by @morriscode
#2140
Source SHA 03f38e0
Triggered by @morriscode
@morriscode
Copy link
Member Author

/update-test-rules

github-actions bot pushed a commit that referenced this pull request Nov 20, 2024
Create vip_impersonation_local_or_spoof.yml by @morriscode
#2140
Source SHA 966c9fb
Triggered by @morriscode
detection-rules/vip_impersonation_local_or_spoof.yml Outdated Show resolved Hide resolved
detection-rules/vip_impersonation_local_or_spoof.yml Outdated Show resolved Hide resolved
detection-rules/vip_impersonation_local_or_spoof.yml Outdated Show resolved Hide resolved
detection-rules/vip_impersonation_local_or_spoof.yml Outdated Show resolved Hide resolved
detection-rules/vip_impersonation_local_or_spoof.yml Outdated Show resolved Hide resolved
@jkamdjou jkamdjou changed the title Create vip_impersonation_local_or_spoof.yml New rule: VIP local_part impersonation from unsolicited sender Nov 20, 2024
@morriscode morriscode enabled auto-merge November 20, 2024 06:34
@jkamdjou jkamdjou disabled auto-merge November 20, 2024 06:58
@jkamdjou jkamdjou merged commit a517e57 into main Nov 20, 2024
3 checks passed
@jkamdjou jkamdjou deleted the morriscode-patch-53 branch November 20, 2024 06:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants