Skip to content

Adding condition for Adobe in detection rule#4567

Open
cybher0808 wants to merge 1 commit into
mainfrom
cybher0808.fn.esc-14527.adobelink
Open

Adding condition for Adobe in detection rule#4567
cybher0808 wants to merge 1 commit into
mainfrom
cybher0808.fn.esc-14527.adobelink

Conversation

@cybher0808
Copy link
Copy Markdown
Member

@cybher0808 cybher0808 commented May 29, 2026

Description

Adding display text open document to logic in a campaign impersonating Adobe brand.

Associated samples

Associated hunts

@cybher0808 cybher0808 requested a review from a team May 29, 2026 18:45
@cybher0808 cybher0808 requested a review from a team as a code owner May 29, 2026 18:45
@cybher0808 cybher0808 self-assigned this May 29, 2026
github-actions Bot added a commit that referenced this pull request May 29, 2026
…n: Adobe with suspicious language and link
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label May 29, 2026
github-actions Bot added a commit that referenced this pull request May 29, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request May 29, 2026
…on: Adobe with suspicious language and link
@cybher0808
Copy link
Copy Markdown
Member Author

cybher0808 commented May 29, 2026

Ran a quick hunt here with a small addition. I wanted to cover FN's that didn't get covered by the rule: Observed IOC: Malicious sender email addresses. I also found additional FN's when running this hunt. Results look good here. Marking R4R.

@cybher0808 cybher0808 added the review-needed Indicates that a PR is waiting for review label May 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant