Skip to content

Commit 3b4c404

Browse files
[Test Rules] [PR #4513] modified rule: VIP impersonation with invoicing request
1 parent d416899 commit 3b4c404

1 file changed

Lines changed: 6 additions & 4 deletions

File tree

detection-rules/4513_impersonation_vip_invoicing_request.yml

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,12 +6,14 @@ source: |
66
type.inbound
77
and any($org_vips,
88
strings.contains(sender.display_name, .display_name)
9-
or strings.contains(sender.display_name,
10-
strings.concat(.first_name, " ", .last_name)
11-
)
129
or strings.contains(sender.display_name,
1310
strings.concat(.last_name, ", ", .first_name)
1411
)
12+
or any(regex.extract(.display_name,
13+
'\A(?P<name>.+?)\s*[\((][^))]*[))]\s*\z'
14+
),
15+
strings.contains(sender.display_name, .named_groups["name"])
16+
)
1517
)
1618
and (
1719
(
@@ -56,4 +58,4 @@ detection_methods:
5658
id: "ced9bb2d-3bc2-59d0-ab4c-48cc1bba975c"
5759
og_id: "a60f89a0-6cd0-5c2d-96de-8800380df407"
5860
testing_pr: 4513
59-
testing_sha: 90a3176084fd25d367a7582d78b2cd7bb9c4b8b5
61+
testing_sha: 8edfcb14502fda5aa8241629f8b4a08bbe1eefc7

0 commit comments

Comments
 (0)