Skip to content

Commit 5d904c1

Browse files
[Shared Samples] [PR #4513] modified rule: PR# 4513 - VIP impersonation with urgent request (strict match, untrusted sender)
1 parent 6b3dfc5 commit 5d904c1

1 file changed

Lines changed: 1 addition & 5 deletions

File tree

detection-rules/4513_impersonation_vip_urgent_request.yml

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -9,12 +9,8 @@ source: |
99
type.inbound
1010
and any($org_vips,
1111
.display_name =~ sender.display_name
12+
or strings.concat(.first_name, " ", .last_name) =~ sender.display_name
1213
or strings.concat(.last_name, ", ", .first_name) =~ sender.display_name
13-
or any(regex.extract(.display_name,
14-
'\A(?P<name>.+?)\s*[\((][^))]*[))]\s*\z'
15-
),
16-
.named_groups["name"] =~ sender.display_name
17-
)
1814
)
1915
and (
2016
any(ml.nlu_classifier(body.current_thread.text).intents,

0 commit comments

Comments
 (0)