Skip to content

Create callback_scam_file_extensions.yml#4300

Open
cybher0808 wants to merge 3 commits intomainfrom
cybher0808.fn.esc-9806.callbackfile
Open

Create callback_scam_file_extensions.yml#4300
cybher0808 wants to merge 3 commits intomainfrom
cybher0808.fn.esc-9806.callbackfile

Conversation

@cybher0808
Copy link
Copy Markdown
Member

@cybher0808 cybher0808 commented Apr 2, 2026

Description

From a runner ping (ESC-9806) - creating new rule to expand on finding incoming emails that have file extensions - callback scams

Associated samples

Associated hunts

@cybher0808 cybher0808 requested a review from a team April 2, 2026 19:25
@cybher0808 cybher0808 requested a review from a team as a code owner April 2, 2026 19:25
@cybher0808 cybher0808 self-assigned this Apr 2, 2026
@cybher0808 cybher0808 added the in-test-rules PR is in our testing suite to collect telemetry label Apr 2, 2026
github-actions Bot added a commit that referenced this pull request Apr 2, 2026
github-actions Bot added a commit that referenced this pull request Apr 2, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 8, 2026
github-actions Bot added a commit that referenced this pull request Apr 14, 2026
github-actions Bot added a commit that referenced this pull request Apr 14, 2026
@cybher0808
Copy link
Copy Markdown
Member Author

Mode results are a bit rough, not sure if I want to keep this revision or change. Will look at a different option for revising logic to get better results or close??

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant