Skip to content

Refine detection rule for Canada Revenue Agency impersonation#4668

Open
cybher0808 wants to merge 1 commit into
mainfrom
cybher0808.fn.esc-15318.craimpersonation
Open

Refine detection rule for Canada Revenue Agency impersonation#4668
cybher0808 wants to merge 1 commit into
mainfrom
cybher0808.fn.esc-15318.craimpersonation

Conversation

@cybher0808

@cybher0808 cybher0808 commented Jun 15, 2026

Copy link
Copy Markdown
Member

Description

Updating this rule with additional nlu classifications for sender, org and language descriptions

Associated samples

Associated hunts

Updated the rule name to include 'CRA' for clarity and enhanced the NLU classification logic to include checks for sender entities and language detection.
@cybher0808 cybher0808 requested a review from a team June 15, 2026 18:11
@cybher0808 cybher0808 requested a review from a team as a code owner June 15, 2026 18:11
@cybher0808 cybher0808 self-assigned this Jun 15, 2026
@cybher0808 cybher0808 added the in-test-rules PR is in our testing suite to collect telemetry label Jun 15, 2026
github-actions Bot added a commit that referenced this pull request Jun 15, 2026
github-actions Bot added a commit that referenced this pull request Jun 15, 2026
@cybher0808

Copy link
Copy Markdown
Member Author

Result look good, this is a quick add on from the last rule. Marking R4R.

@cybher0808 cybher0808 added the review-needed Indicates that a PR is waiting for review label Jun 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant