Skip to content

Create service_abuse_self_service_platform_new_domain.yml - #5307

Merged
D-Bolton merged 4 commits into
mainfrom
daniel.fn.ESC-24627.FN--Construction-bid-solicitation-lure2
Sep 10, 2026
Merged

D-Bolton merged 4 commits into
mainfrom
daniel.fn.ESC-24627.FN--Construction-bid-solicitation-lure2

Conversation

@D-Bolton

@D-Bolton D-Bolton commented Sep 9, 2026

Copy link
Copy Markdown
Member

Description

Detects inbound emails containing links to self-service creation platforms that have a link to a newly registered domain that has a suspicious tld.

Associated samples

Associated hunts

@D-Bolton
D-Bolton marked this pull request as ready for review September 9, 2026 15:19
@D-Bolton
D-Bolton requested a review from a team September 9, 2026 15:19
@D-Bolton
D-Bolton requested a review from a team as a code owner September 9, 2026 15:19
@github-actions github-actions Bot added hunting-required Hunts needed to validate rule efficacy test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules labels Sep 9, 2026
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Test Rules Sync - Excluded

This PR contains rules that use ml.link_analysis, which is not supported in the test-rules environment.

The hunting-required label has been applied. These rules will need to be tested through alternative methods.

github-actions Bot added a commit that referenced this pull request Sep 9, 2026
…f-service platform redirecting to newly registered suspicious domain
github-actions Bot added a commit that referenced this pull request Sep 9, 2026
…Self-service platform redirecting to newly registered suspicious domain
@D-Bolton

D-Bolton commented Sep 9, 2026

Copy link
Copy Markdown
Member Author

Hunt results look good. Tagging for review.

@D-Bolton D-Bolton added the review-needed Indicates that a PR is waiting for review label Sep 9, 2026
@zoomequipd zoomequipd self-assigned this Sep 10, 2026
@D-Bolton
D-Bolton added this pull request to the merge queue Sep 10, 2026
Merged via the queue into main with commit 589b7e8 Sep 10, 2026
5 checks passed
@D-Bolton
D-Bolton deleted the daniel.fn.ESC-24627.FN--Construction-bid-solicitation-lure2 branch September 10, 2026 15:02
github-actions Bot added a commit that referenced this pull request Sep 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hunting-required Hunts needed to validate rule efficacy review-needed Indicates that a PR is waiting for review test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants