Skip to content

Conversation

@IndiaAce
Copy link
Member

@IndiaAce IndiaAce commented Nov 6, 2025

Description

From a runner. There's an opportunity here to create some detection-in-depth by creating a rule for emails with an attached zip that contain language suggesting "the password for the encrypted file is: ___" sales invoked ADE and put a new rule in their env, and we have the encrypted attachment detection as well but again, the more the merrier.

Associated samples

Associated hunts

@IndiaAce IndiaAce requested a review from a team as a code owner November 6, 2025 21:48
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Nov 6, 2025
github-actions bot added a commit that referenced this pull request Nov 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant