Skip to content

Commit 54cb9ce

Browse files
[Test Rules] [PR #4513] modified rule: VIP impersonation with BEC language (near match, untrusted sender)
1 parent 02ef058 commit 54cb9ce

1 file changed

Lines changed: 7 additions & 8 deletions

File tree

detection-rules/4513_impersonation_vip_bec_loose.yml

Lines changed: 7 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -9,19 +9,18 @@ source: |
99
type.inbound
1010
and any($org_vips,
1111
0 <= strings.ilevenshtein(sender.display_name, .display_name) < 4
12+
or 0 <= strings.ilevenshtein(sender.display_name,
13+
strings.concat(.first_name,
14+
" ",
15+
.last_name
16+
)
17+
) < 4
1218
or 0 <= strings.ilevenshtein(sender.display_name,
1319
strings.concat(.last_name,
1420
", ",
1521
.first_name
1622
)
1723
) < 4
18-
or any(regex.extract(.display_name,
19-
'\A(?P<name>.+?)\s*[\((][^))]*[))]\s*\z'
20-
),
21-
0 <= strings.ilevenshtein(sender.display_name,
22-
.named_groups["name"]
23-
) < 4
24-
)
2524
)
2625
and any(ml.nlu_classifier(body.current_thread.text).intents,
2726
.name == "bec" and .confidence in ("medium", "high")
@@ -66,4 +65,4 @@ detection_methods:
6665
id: "af52ee6e-31f3-52e7-ba94-1e460c89628f"
6766
og_id: "303081da-6850-5ba6-9589-c3dc7673320e"
6867
testing_pr: 4513
69-
testing_sha: 8edfcb14502fda5aa8241629f8b4a08bbe1eefc7
68+
testing_sha: 4e4a7760ad81eb7d66ae5f3e4701e7923ebb1f45

0 commit comments

Comments
 (0)