Skip to content

Commit bce0247

Browse files
[Shared Samples] [PR #4515] modified rule: PR# 4515 - Fake thread with suspicious indicators
1 parent fa05e05 commit bce0247

1 file changed

Lines changed: 28 additions & 10 deletions

File tree

detection-rules/4515_fake_thread_suspicious_indicators.yml

Lines changed: 28 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -120,21 +120,39 @@ source: |
120120
// body contains name of VIP
121121
(
122122
any($org_vips,
123-
strings.icontains(body.html.inner_text, .display_name)
124-
or strings.icontains(body.html.inner_text,
125-
strings.concat(.first_name, " ", .last_name)
123+
.display_name != ""
124+
and strings.icontains(body.html.inner_text, .display_name)
125+
or (
126+
.first_name != ""
127+
and .last_name != ""
128+
and strings.icontains(body.html.inner_text,
129+
strings.concat(.first_name, " ", .last_name)
130+
)
126131
)
127-
or strings.icontains(body.html.inner_text,
128-
strings.concat(.last_name, ", ", .first_name)
132+
or (
133+
.first_name != ""
134+
and .last_name != ""
135+
and strings.icontains(body.html.inner_text,
136+
strings.concat(.last_name, ", ", .first_name)
137+
)
129138
)
130139
)
131140
or any($org_vips,
132-
strings.icontains(body.plain.raw, .display_name)
133-
or strings.icontains(body.plain.raw,
134-
strings.concat(.first_name, " ", .last_name)
141+
.display_name != ""
142+
and strings.icontains(body.plain.raw, .display_name)
143+
or (
144+
.first_name != ""
145+
and .last_name != ""
146+
and strings.icontains(body.plain.raw,
147+
strings.concat(.first_name, " ", .last_name)
148+
)
135149
)
136-
or strings.icontains(body.plain.raw,
137-
strings.concat(.last_name, ", ", .first_name)
150+
or (
151+
.first_name != ""
152+
and .last_name != ""
153+
and strings.icontains(body.plain.raw,
154+
strings.concat(.last_name, ", ", .first_name)
155+
)
138156
)
139157
)
140158
),

0 commit comments

Comments
 (0)