Skip to content

Create link_susp_tld_hosting_clientjs.yml - #5245

Merged
keaton-sublime merged 9 commits into
mainfrom
keaton-sublime.FN.ESC-23989.susp_tld_cf_beacon
Sep 11, 2026
Merged

keaton-sublime merged 9 commits into
mainfrom
keaton-sublime.FN.ESC-23989.susp_tld_cf_beacon

Conversation

@keaton-sublime

@keaton-sublime keaton-sublime commented Sep 2, 2026

Copy link
Copy Markdown
Member

Description

Matching messages with links that resolve to suspicious TLDs and load the CF beaon.js script, while hosting a client.js file locally to that suspicious TLD host.

Associated samples

Associated hunts

@keaton-sublime keaton-sublime added the in-test-rules PR is in our testing suite to collect telemetry label Sep 2, 2026
@github-actions github-actions Bot added hunting-required Hunts needed to validate rule efficacy test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules labels Sep 2, 2026
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Test Rules Sync - Excluded

This PR contains rules that use ml.link_analysis, which is not supported in the test-rules environment.

The hunting-required label has been applied. These rules will need to be tested through alternative methods.

@github-actions github-actions Bot removed the in-test-rules PR is in our testing suite to collect telemetry label Sep 2, 2026
github-actions Bot added a commit that referenced this pull request Sep 2, 2026
@keaton-sublime keaton-sublime added the review-needed Indicates that a PR is waiting for review label Sep 9, 2026
@keaton-sublime

Copy link
Copy Markdown
Member Author

marking review needed/ready for review - the telemetry on this has been very light, but multi-hunts have not shown FPs.

@keaton-sublime
keaton-sublime marked this pull request as ready for review September 9, 2026 17:13
@keaton-sublime
keaton-sublime requested a review from a team September 9, 2026 17:13
@keaton-sublime
keaton-sublime requested a review from a team as a code owner September 9, 2026 17:13
github-actions Bot added a commit that referenced this pull request Sep 9, 2026
@zoomequipd zoomequipd self-assigned this Sep 10, 2026
Comment thread detection-rules/link_susp_tld_hosting_clientjs.yml

@zoomequipd zoomequipd left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

non blocking feedback

Comment thread detection-rules/link_susp_tld_hosting_clientjs.yml Outdated
Comment thread detection-rules/link_susp_tld_hosting_clientjs.yml Outdated
Comment thread detection-rules/link_susp_tld_hosting_clientjs.yml Outdated
Comment thread detection-rules/link_susp_tld_hosting_clientjs.yml
keaton-sublime and others added 3 commits September 11, 2026 09:20
github-actions Bot added a commit that referenced this pull request Sep 11, 2026
@keaton-sublime
keaton-sublime added this pull request to the merge queue Sep 11, 2026
Merged via the queue into main with commit 9fb83c3 Sep 11, 2026
4 checks passed
@keaton-sublime
keaton-sublime deleted the keaton-sublime.FN.ESC-23989.susp_tld_cf_beacon branch September 11, 2026 13:48
github-actions Bot added a commit that referenced this pull request Sep 11, 2026
missingn0pe pushed a commit that referenced this pull request Sep 21, 2026
Co-authored-by: CI Bot <hello@sublimesecurity.com>
Co-authored-by: Brandon Murphy <4827852+zoomequipd@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hunting-required Hunts needed to validate rule efficacy review-needed Indicates that a PR is waiting for review test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants