Skip to content

Conversation

@IndiaAce
Copy link
Member

Description

Noticed some FNs in a grey area in our detections and wanted to create a little defense in-depth. I want to let this sit in test rules for a few days to see telemetry before continuing to work on this logic. The intention here is to detect on promotional-looking emails for people signing up for new credit cards but are then sent to WhatsApp for the application process.

Associated samples

Associated hunts

@IndiaAce IndiaAce requested a review from a team as a code owner October 22, 2025 14:21
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Oct 22, 2025
github-actions bot added a commit that referenced this pull request Oct 22, 2025
github-actions bot added a commit that referenced this pull request Oct 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant