Skip to content

Conversation

@D-Bolton
Copy link
Member

@D-Bolton D-Bolton commented Jan 22, 2026

Description

Detects messages containing only URL shorteners with copy-paste instructions and high-confidence credential theft language, typically used to evade URL analysis by requiring manual URL entry.

Associated samples

Associated hunts

@D-Bolton D-Bolton marked this pull request as ready for review January 22, 2026 17:04
@D-Bolton D-Bolton requested a review from a team as a code owner January 22, 2026 17:04
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Jan 22, 2026
github-actions bot added a commit that referenced this pull request Jan 22, 2026
github-actions bot added a commit that referenced this pull request Jan 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant