sublime-rules
sublime-rules copied to clipboard
LWescott Update credential_phishing_esign_document_notification.yml
Description
From a runner expanding coverage to include any character within a bound of 4 between e and doc.
Associated samples
Associated hunts
-Hunt 1 showing exclusive matches on the change. -Hunt 2 updated hunt showing all matches
Telemetry is awful on this, taking out of R4R
net-new telemetry on these look good, the customer hits with "likely_benign" were mostly pen tests... marking as ready for review.