Skip to content

Create link_self_sender_ip_check.yml#4667

Open
D-Bolton wants to merge 4 commits into
mainfrom
daniel.fn.ESC-15529.FN--Account-compromise-phishing
Open

Create link_self_sender_ip_check.yml#4667
D-Bolton wants to merge 4 commits into
mainfrom
daniel.fn.ESC-15529.FN--Account-compromise-phishing

Conversation

@D-Bolton

@D-Bolton D-Bolton commented Jun 15, 2026

Copy link
Copy Markdown
Member

Description

Detects messages where the sender and recipient are the same address and the email contains a link that accesses ipinfo.io

Associated samples

Associated hunts

@D-Bolton D-Bolton marked this pull request as ready for review June 15, 2026 17:09
@D-Bolton D-Bolton requested a review from a team June 15, 2026 17:09
@D-Bolton D-Bolton requested a review from a team as a code owner June 15, 2026 17:09
github-actions Bot added a commit that referenced this pull request Jun 15, 2026
@github-actions github-actions Bot added test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules hunting-required Hunts needed to validate rule efficacy labels Jun 15, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Test Rules Sync - Excluded

This PR contains rules that use ml.link_analysis, which is not supported in the test-rules environment.

The hunting-required label has been applied. These rules will need to be tested through alternative methods.

github-actions Bot added a commit that referenced this pull request Jun 15, 2026
github-actions Bot added a commit that referenced this pull request Jun 17, 2026
…er with IP geolocation check and suspicious link behavior
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hunting-required Hunts needed to validate rule efficacy test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant