SwiftFilter
SwiftFilter copied to clipboard
Exchange Transport rules to detect and enable response to phishing
(bc1|[13])[a-km-zA-HJ-NP-Z1-9]{25,34}(\s|$|\.(?!\w)) Most successful filter I know of for pattern match a bitcoin address.
"centre" in Quarantine-Content.txt is admittedly USA-centric. However, I don't see a lot of legitimate emails coming through with that in it for US-based customers.
Fixed typo in quarantine.messaging.microsoft.com
Fixed some instances of quarantine being misspelled. Fixes #5
Believe that dot in that domain should also be escaped.
"quaratine.messaging.microsoft.com" is missing an 'n'
How do I import the sets from these rules into Exchange Online?
Hai, As `Å` is used by all the Scandinavian countries I added those TLDs. I don't know if you also want to add `Ä,Æ,Ö,Ø` but those would also fall under...