Create fake_canada_taxrevenue_T4.yml#4126
Conversation
…ue Agency with attachment
…n: Canada Revenue Agency with attachment
…venue Agency with attachment
…tion: Canada Revenue Agency with attachment
|
In test-rules are a mixture of malicious and benign, the benign samples match on suspicious strings from file.explode. I have included hunting customer environments and they look suspicious/malicious - check in Notion for clarification. |
Hunted again and found a better way to find malicious samples.
…venue Agency with attachment
…tion: Canada Revenue Agency with attachment
|
Test-rules/multi-hunt outcome are looking good in this case from revisions. Majority of the samples are malicious. |
IndiaAce
left a comment
There was a problem hiding this comment.
I've requested a few changes, going to remove the review-needed label for the time being. Feel free to add it back when you're ready for a re-review!
…tion: Canada Revenue Agency with attachment
…venue Agency with attachment
Shared Samples Sync - ExcludedThis PR contains 14 rules, which exceeds the maximum of 10 rules allowed per PR for automatic syncing. This limit helps ensure the shared-samples environment remains manageable. If you need to test these rules, consider:
|
…ue Agency with attachment
…n: Canada Revenue Agency with attachment
…ation: Canada Revenue Agency with attachment
Refactored conditions for detecting fake Canada tax revenue emails by consolidating regex checks and removing redundant conditions.
…ation: Canada Revenue Agency with attachment
…tion: Canada Revenue Agency with attachment
…venue Agency with attachment
|
Waiting for this hunt search to finish. Results have been shared from Mode and SS. Some environments have failed after hunting see ESC. Made a few changes since there were FP's flagged with my previous written rule. Added the Marking for R4R. |
|
I think we can simplify this logic a bit without needing all the topic negations and extra stuff, I've been running some hunts this morning that's just "says its from CRA, with cred theft, and isn't actually from them" let me know your thoughts but I think it's doing well. Feel free to grab this. https://hunt.limeseed.email/hunts/dcd0dc39-7afd-4aea-bf40-a17b6480a35a Gonna remove review-needed for now but feel free to message me if you want a re-review on it. |
|
I was a bit hesitant a bit since I felt like my last rule proposed felt like it was a mouth full, I like this clean up. Good approach here. I doubled check if I missed any. I reran after sharing the multi-hunt results - solid count here --> hunt & ran a net-new, validation check. TY! @IndiaAce |
…venue Agency with attachment
…ation: Canada Revenue Agency with attachment
…tion: Canada Revenue Agency with attachment
Description
Detects messages impersonating the Canada Revenue Agency (CRA) with attachments, using common tax-related subjects in both English and French, and containing CRA-related content in the message body.
Associated samples
Associated hunts