Skip to content

Conversation

@IndiaAce
Copy link
Member

Description

From a runner, want to let this sit for a few days to see how it does and iterate from there. Hopefully we get some samples.

Expanding the scope of the sendgrid alert to account for impersonation that doesn't contain sendgrid in the sender name but still is very much sendgrid impersonation.

Associated samples

Associated hunts

  • Hunt 1 - Exclusive new matches (in SS)
  • Hunt 2 - full propsal changes

@IndiaAce IndiaAce requested a review from a team as a code owner October 31, 2025 16:59
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Oct 31, 2025
@IndiaAce IndiaAce added the review-needed Indicates that a PR is waiting for review label Nov 5, 2025
@IndiaAce
Copy link
Member Author

IndiaAce commented Nov 5, 2025

Net-new tlemetry looked good in test rules. The likely_benigns are misses on AS and is indicative of the activity we'd like to see. There's a client with a bunch of benigns that we have access to, I checked those all and it was part of a pen test... marking as ready for review!

@aidenmitchell aidenmitchell added this pull request to the merge queue Nov 7, 2025
Merged via the queue into main with commit 0b052a9 Nov 7, 2025
3 checks passed
@aidenmitchell aidenmitchell deleted the LWescott_update_sendgrid_detection branch November 7, 2025 18:04
github-actions bot added a commit that referenced this pull request Nov 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants