Skip to content

Add detection rule for Claude impersonation #4683

Open
cybher0808 wants to merge 5 commits into
mainfrom
cybher0808.fn.esc-15623.fakeclaude
Open

Add detection rule for Claude impersonation #4683
cybher0808 wants to merge 5 commits into
mainfrom
cybher0808.fn.esc-15623.fakeclaude

Conversation

@cybher0808

@cybher0808 cybher0808 commented Jun 16, 2026

Copy link
Copy Markdown
Member

Description

This rule detects impersonation of Anthropic or Claude using newly registered domains. It flags messages based on sender display names and checks for domain age and specific content in the message.

Associated samples

Associated hunts

This rule detects impersonation of Anthropic or Claude using newly registered domains. It flags messages based on sender display names and checks for domain age and specific content in the message.
@cybher0808 cybher0808 requested a review from a team June 16, 2026 18:15
@cybher0808 cybher0808 requested a review from a team as a code owner June 16, 2026 18:15
@cybher0808 cybher0808 self-assigned this Jun 16, 2026
@cybher0808 cybher0808 added the in-test-rules PR is in our testing suite to collect telemetry label Jun 16, 2026
github-actions Bot added a commit that referenced this pull request Jun 16, 2026
github-actions Bot added a commit that referenced this pull request Jun 16, 2026
Removed commented-out conditions for body links in impersonation detection rule.
github-actions Bot added a commit that referenced this pull request Jun 16, 2026
github-actions Bot added a commit that referenced this pull request Jun 16, 2026
…tion: Claude with newly registered domains
github-actions Bot added a commit that referenced this pull request Jun 18, 2026
…tion: Claude with newly registered domains
github-actions Bot added a commit that referenced this pull request Jun 18, 2026
github-actions Bot added a commit that referenced this pull request Jun 18, 2026
github-actions Bot added a commit that referenced this pull request Jun 19, 2026
…tion: Claude with newly registered domains
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant