Skip to content

Commit dfb6493

Browse files
[Shared Samples] [PR #4513] modified rule: PR# 4513 - VIP impersonation with urgent request (strict match, untrusted sender)
1 parent ddb0772 commit dfb6493

1 file changed

Lines changed: 11 additions & 3 deletions

File tree

detection-rules/4513_impersonation_vip_urgent_request.yml

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,9 +8,17 @@ severity: "high"
88
source: |
99
type.inbound
1010
and any($org_vips,
11-
.display_name =~ sender.display_name
12-
or strings.concat(.first_name, " ", .last_name) =~ sender.display_name
13-
or strings.concat(.last_name, ", ", .first_name) =~ sender.display_name
11+
(.display_name != "" and .display_name =~ sender.display_name)
12+
or (
13+
.first_name != ""
14+
and .last_name != ""
15+
and strings.concat(.first_name, " ", .last_name) =~ sender.display_name
16+
)
17+
or (
18+
.first_name != ""
19+
and .last_name != ""
20+
and strings.concat(.last_name, ", ", .first_name) =~ sender.display_name
21+
)
1422
)
1523
and (
1624
any(ml.nlu_classifier(body.current_thread.text).intents,

0 commit comments

Comments
 (0)