Skip to content

Conversation

@brycampbell
Copy link
Member

Description

This rule is designed to identify suspicious OpenAI style phishing content, using both logo detect (TBD) and levenshtein logic to determine whether brand impersonation is present. Including the legimate sending domains should reduce the risk of false positives.

Associated samples

this sample is a phish

Associated hunts

Screenshot (insights)

@brycampbell brycampbell requested a review from a team as a code owner January 15, 2026 16:18
@github-actions github-actions bot added test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules hunting-required Hunts needed to validate rule efficacy labels Jan 15, 2026
github-actions bot added a commit to aidenmitchell/sublime-rules that referenced this pull request Jan 16, 2026
…: OpenAI with payment issues and suspicious links
github-actions bot added a commit to aidenmitchell/sublime-rules that referenced this pull request Jan 16, 2026
github-actions bot added a commit to aidenmitchell/sublime-rules that referenced this pull request Jan 16, 2026
…: OpenAI with payment issues and suspicious links
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hunting-required Hunts needed to validate rule efficacy test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant