Skip to content

Commit f2a7de2

Browse files
[PR #3371] modified rule: Credential phishing: Suspicious Nifty.com sender address
1 parent 1935d84 commit f2a7de2

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

detection-rules/3371_credential_phishing_nifty.com_domain_abuse.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
name: "Credential phishing: Nifty.com platform abuse"
1+
name: "Credential phishing: Suspicious Nifty.com sender address"
22
description: "Detects emails from nifty.com where the sender's local part matches a recipient's local part or organizational SLD, which has been observed in credential harvesting campaigns"
33
type: "rule"
44
severity: "medium"
@@ -29,4 +29,4 @@ detection_methods:
2929
id: "2feb95a2-78f4-569b-8d33-659ac7b17e3f"
3030
og_id: "370cfdac-4976-59a1-ae1f-7cd5594eb958"
3131
testing_pr: 3371
32-
testing_sha: c80a4a02dcffe7056f91513374fa805d1ad01a17
32+
testing_sha: bce1db4513a6dfe62e98e01ab8c5980c606fc837

0 commit comments

Comments
 (0)