-
Notifications
You must be signed in to change notification settings - Fork 86
Create impersonation_openai.yml #2952
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Hunting has identified some domains that are identified as part of the Levenshtein logic, i will add a negation in for the legitimate ones. |
|
https://platform.sublime.security/messages/hunt?huntId=0198144c-8f1e-7d4a-b520-97cb9f307658 This hunt includes some negation for a legitimate platform. |
|
/update-test-rules |
Create impersonation_openai.yml by @brycampbell #2952 Source SHA 493cf3c Triggered by @brycampbell
Remove deprecated profile for messages, replaced with benign profile
|
/update-test-rules |
|
Logo is in, adding in another negation. |
|
Hunting with some additional edits.
|
zoomequipd
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
still has many benign matches.
Co-authored-by: Brandon Murphy <4827852+zoomequipd@users.noreply.github.com>
Co-authored-by: Brandon Murphy <4827852+zoomequipd@users.noreply.github.com>
|
removing review needed label until feedback is addressed |
Co-authored-by: Brandon Murphy <4827852+zoomequipd@users.noreply.github.com>
Including type confusables to catch missing samples: https://platform.sublime.security/messages/4fdfc94e16d5027b418690695d87b2a9d312000ab9a0f23a6759204b23b1cadb?preview_id=019b57ab-620a-70fe-bc70-e983741bb170
Add in negation to avoid legit ChatGPT purchases from Apple App store.
Description
This rule is designed to identify suspicious OpenAI style phishing content, using both logo detect (TBD) and levenshtein logic to determine whether brand impersonation is present. Including the legimate sending domains should reduce the risk of false positives.
Associated samples
Sample 1
This sample is responsible for display name brand abuse.
Sample 2
this sample is a phish
Associated hunts
Screenshot (insights)