Skip to content

Commit e5af27a

Browse files
[PR #3433] modified rule: Brand Impersonation: ShareFile
1 parent c852c50 commit e5af27a

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

detection-rules/3433_impersonation_sharefile.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -37,8 +37,9 @@ source: |
3737
0 < length(attachments) <= 5
3838
and (
3939
all(attachments, .file_type in $file_types_images)
40-
// allow for one non-PDF attachment, which has been observed added as an evasion tactic
41-
or ratio(attachments, .file_extension in ("pdf")) == 0.5
40+
or (
41+
length(filter(attachments, .file_type == "pdf")) == 1
42+
)
4243
)
4344
and any(attachments,
4445
any(file.explode(.),
@@ -107,4 +108,4 @@ detection_methods:
107108
id: "52895b87-8a4f-5ac7-b378-1dbd708a20d9"
108109
og_id: "f8330307-67fe-5b49-b850-bfdc17955aea"
109110
testing_pr: 3433
110-
testing_sha: e29c2c082291a5502b2774e21472669538c6f030
111+
testing_sha: 9b1c944bc3d2921cdd3e7f3e9e21bb3eb2d54516

0 commit comments

Comments
 (0)