Skip to content

Commit df1416a

Browse files
[Shared Samples] [PR #4515] modified rule: PR# 4515 - Service abuse: Trello board invitation with VIP impersonation
1 parent 3a35e77 commit df1416a

1 file changed

Lines changed: 9 additions & 12 deletions

File tree

detection-rules/4515_service_abuse_trello_board_invite_vip.yml

Lines changed: 9 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -30,12 +30,10 @@ source: |
3030
any($org_vips,
3131
strings.icontains(..display_text, .display_name)
3232
or strings.icontains(..display_text,
33-
strings.concat(.last_name, ", ", .first_name)
33+
strings.concat(.first_name, " ", .last_name)
3434
)
35-
or any(regex.extract(.display_name,
36-
'\A(?P<name>.+?)\s*[\((][^))]*[))]\s*\z'
37-
),
38-
strings.icontains(...display_text, .named_groups["name"])
35+
or strings.icontains(..display_text,
36+
strings.concat(.last_name, ", ", .first_name)
3937
)
4038
)
4139
// org sld as the board name
@@ -53,19 +51,18 @@ source: |
5351
and strings.iends_with(.display_text, 'From')
5452
and any($org_vips,
5553
strings.icontains(..display_text, .display_name)
54+
or strings.icontains(..display_text,
55+
strings.concat(.first_name,
56+
" ",
57+
.last_name
58+
)
59+
)
5660
or strings.icontains(..display_text,
5761
strings.concat(.last_name,
5862
", ",
5963
.first_name
6064
)
6165
)
62-
or any(regex.extract(.display_name,
63-
'\A(?P<name>.+?)\s*[\((][^))]*[))]\s*\z'
64-
),
65-
strings.icontains(...display_text,
66-
.named_groups["name"]
67-
)
68-
)
6966
)
7067
)
7168
)

0 commit comments

Comments
 (0)