Skip to content

Conversation

@brycampbell
Copy link
Member

Description

This rule is designed to detect the impersonation of Google Workspace, where the sample relies on logic inside the email including correct imagery, and excludes the forwaded contents (to spam@ or IT helpdesks)

Associated hunts

This hunt appears to be a specific limited campaign, so this rule will require additional coverage if its limited to this 2 day campaign

Screenshot (insights)

This image excludes sensitive recipients.

image

@brycampbell brycampbell requested a review from a team as a code owner November 5, 2025 15:13
@brycampbell brycampbell added the in-test-rules PR is in our testing suite to collect telemetry label Nov 5, 2025
@brycampbell brycampbell added the hunting-required Hunts needed to validate rule efficacy label Nov 5, 2025
github-actions bot added a commit that referenced this pull request Nov 5, 2025
@brycampbell
Copy link
Member Author

Here is a canonical of an interactive example:

17e01859-333e-4c3f-bafe-11a6e5635d67

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hunting-required Hunts needed to validate rule efficacy in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant