Skip to content

Update impersonation_microsoft_teams.yml#4375

Open
markmsublime wants to merge 2 commits intomainfrom
markmsublime.FN.ESC-11690.teams_impersonation
Open

Update impersonation_microsoft_teams.yml#4375
markmsublime wants to merge 2 commits intomainfrom
markmsublime.FN.ESC-11690.teams_impersonation

Conversation

@markmsublime
Copy link
Copy Markdown
Member

Description

expanding scope of this rule to look for impersonation techniques in body current thread, while adding a new negation for sending through legitimate Microsoft infrastructure to negate FPs

Associated samples

Associated hunts

@markmsublime markmsublime requested a review from a team April 21, 2026 13:53
@markmsublime markmsublime requested a review from a team as a code owner April 21, 2026 13:53
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Apr 21, 2026
github-actions Bot added a commit that referenced this pull request Apr 21, 2026
github-actions Bot added a commit that referenced this pull request Apr 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant