Skip to content

Create self_sender_cred_theft_short_path_link.yml#4378

Open
D-Bolton wants to merge 2 commits intomainfrom
daniel.fn.ESC-11425.FN--Credential-phishing-with-self-sender-pattern
Open

Create self_sender_cred_theft_short_path_link.yml#4378
D-Bolton wants to merge 2 commits intomainfrom
daniel.fn.ESC-11425.FN--Credential-phishing-with-self-sender-pattern

Conversation

@D-Bolton
Copy link
Copy Markdown
Member

@D-Bolton D-Bolton commented Apr 21, 2026

Description

Detects messages sent to oneself containing links with single character paths and credential theft language, commonly used to bypass security filters and deliver malicious content.

Associated samples

Associated hunts

github-actions Bot added a commit that referenced this pull request Apr 21, 2026
@D-Bolton D-Bolton marked this pull request as ready for review April 21, 2026 21:58
@D-Bolton D-Bolton requested a review from a team April 21, 2026 21:58
@D-Bolton D-Bolton requested a review from a team as a code owner April 21, 2026 21:58
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Apr 21, 2026
github-actions Bot added a commit that referenced this pull request Apr 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant