Skip to content

Commit fe8bd5b

Browse files
[Test Rules] [PR #4611] modified rule: Link: Remittance payment request with suspicious indicators
1 parent ebf9a83 commit fe8bd5b

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

detection-rules/4611_link_remittance_suspicious.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,9 @@ source: |
66
type.inbound
77
and strings.icontains(body.plain.raw, "business days")
88
and strings.icontains(body.plain.raw, "account")
9-
and any(body.links, strings.icontains(.href_url.path, "remittance"))
9+
and any(filter(body.links, .href_url.domain.root_domain not in $tranco_10k),
10+
strings.icontains(.href_url.path, "remittance")
11+
)
1012
attack_types:
1113
- "BEC/Fraud"
1214
- "Credential Phishing"
@@ -18,4 +20,4 @@ detection_methods:
1820
id: "06d21fb0-41f5-58c1-82cc-2a2660be213f"
1921
og_id: "10dde1bf-480e-589b-95a3-3f81b811b667"
2022
testing_pr: 4611
21-
testing_sha: 580e01e20708144c999417b840ea538b744464ea
23+
testing_sha: 987d225894e9eeda525053dd8c51758b999a179b

0 commit comments

Comments
 (0)