Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create suspicious_sender_display_name_procedurally_generated_blob.yml #2107

Open
wants to merge 7 commits into
base: main
Choose a base branch
from

Conversation

morriscode
Copy link
Member

Description

New rule to text generated blobs of text in the sender display name. This has been observed in several campaigns, most likely for tracking purposes or obfuscation.

Associated hunts

@morriscode morriscode requested a review from a team as a code owner November 12, 2024 22:53
@morriscode
Copy link
Member Author

/update-test-rules

github-actions bot pushed a commit that referenced this pull request Nov 12, 2024
Create suspicious_sender_display_name_procedurally_generated_blob.yml by @morriscode
#2107
Source SHA be93a3e
Triggered by @morriscode
@morriscode
Copy link
Member Author

/update-test-rules

github-actions bot pushed a commit that referenced this pull request Nov 13, 2024
Create suspicious_sender_display_name_procedurally_generated_blob.yml by @morriscode
#2107
Source SHA 69f23d8
Triggered by @morriscode
@morriscode
Copy link
Member Author

/update-test-rules

github-actions bot pushed a commit that referenced this pull request Nov 14, 2024
Create suspicious_sender_display_name_procedurally_generated_blob.yml by @morriscode
#2107
Source SHA fbe3a2e
Triggered by @morriscode
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants