Skip to content

Update credential_theft_cloud_storage_impersonation.yml#4372

Open
JFarina5 wants to merge 1 commit intomainfrom
JFarina5.FN.ESC-11639.cloud.theft.impersonation
Open

Update credential_theft_cloud_storage_impersonation.yml#4372
JFarina5 wants to merge 1 commit intomainfrom
JFarina5.FN.ESC-11639.cloud.theft.impersonation

Conversation

@JFarina5
Copy link
Copy Markdown
Member

@JFarina5 JFarina5 commented Apr 20, 2026

Description

Adding body.current_thread.link logic to match on links where the entire URL path is an alphanumeric string of 20 or more characters

Associated samples

Associated hunts

@JFarina5 JFarina5 requested a review from a team April 20, 2026 21:31
@JFarina5 JFarina5 requested a review from a team as a code owner April 20, 2026 21:31
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Apr 20, 2026
github-actions Bot added a commit that referenced this pull request Apr 20, 2026
github-actions Bot added a commit that referenced this pull request Apr 20, 2026
…rsonation with credential theft indicators
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant