sublime-rules
sublime-rules copied to clipboard
Create vendor_compromise_microsoft.yml
trafficstars
Description
Message contains suspicious links and Microsoft impersonation from a sender common to your environment. Indicative of vendor compromise.
Associated samples
- https://platform.sublime.security/messages/88497823a501feb43fb1de2a71417f7551b63a9436a28167d078e648a5737cc1?preview_id=019565e2-8c2a-713d-9351-eb68745fad30
/update-test-rules
/update-test-rules
/update-test-rules
/update-test-rules
/update-test-rules
will let the latest rev work for a couple days
A more recent hunt
Closing this rule is no closer to deployment