Skip to content

Update fake_thread_suspicious_indicators.yml#4289

Open
IndiaAce wants to merge 2 commits intomainfrom
india.fn.ESC-10039.update_fake_thread
Open

Update fake_thread_suspicious_indicators.yml#4289
IndiaAce wants to merge 2 commits intomainfrom
india.fn.ESC-10039.update_fake_thread

Conversation

@IndiaAce
Copy link
Copy Markdown
Member

@IndiaAce IndiaAce commented Apr 1, 2026

Description

Resolving an FN that came through with a fake thread and a mis-aligned mailto link in the body of the message. Added a freemailer check to resolve some FPs and to "solve the problem I'm seeing today" which was these attacks are coming from freemailers.

Associated samples

Associated hunts

Screenshot (insights)

@IndiaAce IndiaAce requested a review from a team April 1, 2026 14:15
@IndiaAce IndiaAce requested a review from a team as a code owner April 1, 2026 14:15
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Apr 1, 2026
github-actions bot added a commit that referenced this pull request Apr 1, 2026
github-actions bot added a commit that referenced this pull request Apr 7, 2026
github-actions bot added a commit that referenced this pull request Apr 7, 2026
github-actions bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant