Skip to content

Update credential_theft_cloud_storage_impersonation.yml#4691

Open
JFarina5 wants to merge 2 commits into
mainfrom
JFarina5.FN.ESC-15632.cred.theft.cloud.storage
Open

Update credential_theft_cloud_storage_impersonation.yml#4691
JFarina5 wants to merge 2 commits into
mainfrom
JFarina5.FN.ESC-15632.cred.theft.cloud.storage

Conversation

@JFarina5

@JFarina5 JFarina5 commented Jun 17, 2026

Copy link
Copy Markdown
Member

Description

Updating logic to account for samples with a unusual amount of links, additional regex matching, and links with unusual characters in its path

Associated samples

Associated hunts

@JFarina5 JFarina5 requested a review from a team June 17, 2026 16:57
@JFarina5 JFarina5 requested a review from a team as a code owner June 17, 2026 16:57
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Jun 17, 2026
github-actions Bot added a commit that referenced this pull request Jun 17, 2026
github-actions Bot added a commit that referenced this pull request Jun 17, 2026
…rsonation with credential theft indicators
github-actions Bot added a commit that referenced this pull request Jun 23, 2026
…mpersonation with credential theft indicators
github-actions Bot added a commit that referenced this pull request Jun 23, 2026
@JFarina5

Copy link
Copy Markdown
Member Author

Not a ton of telemetry, but good telemetry. Hunt in description has been updated, marking r4r.

@JFarina5 JFarina5 added the review-needed Indicates that a PR is waiting for review label Jun 23, 2026
""
)
)
or any(body.links, regex.icontains(.href_url.url, '(?:;[^/]*){3,}'))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i think we actually have a URL decoder that is designed to catch the URL being used in these messages.

@zoomequipd zoomequipd self-assigned this Jun 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants