Skip to content

Commit 41b1ff7

Browse files
[Shared Samples] [PR #4513] modified rule: PR# 4513 - VIP impersonation with w2 request with reply-to mismatch
1 parent 5d904c1 commit 41b1ff7

1 file changed

Lines changed: 3 additions & 5 deletions

File tree

detection-rules/4513_impersonation_vip_w2_request.yml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,10 @@ source: |
88
any($org_vips,
99
strings.contains(sender.display_name, .display_name)
1010
or strings.contains(sender.display_name,
11-
strings.concat(.last_name, ", ", .first_name)
11+
strings.concat(.first_name, " ", .last_name)
1212
)
13-
or any(regex.extract(.display_name,
14-
'\A(?P<name>.+?)\s*[\((][^))]*[))]\s*\z'
15-
),
16-
strings.contains(sender.display_name, .named_groups["name"])
13+
or strings.contains(sender.display_name,
14+
strings.concat(.last_name, ", ", .first_name)
1715
)
1816
)
1917
or any(regex.extract(sender.display_name, '^(?<first>\S+)\s+(?<second>\S+)$'),

0 commit comments

Comments
 (0)