Skip to content

Conversation

@missingn0pe
Copy link
Member

This rule detects messages impersonating AuthentiSign based on various criteria, including display name, domain, subject, and body content. It identifies potential phishing and fraud attempts originating from non-AuthentiSign or spoofed domains.

Associated samples

- Sample 1
- Sample 2

Associated hunts

- Hunt 1
- Hunt 2

This rule detects messages impersonating AuthentiSign based on various criteria, including display name, domain, subject, and body content. It identifies potential phishing and fraud attempts originating from non-AuthentiSign or spoofed domains.
@missingn0pe missingn0pe requested a review from a team as a code owner December 29, 2025 22:42
@missingn0pe
Copy link
Member Author

Requested logo coverage & can add logic after request is complete. Link is behind sendgrid so final dom could help but will need to lean on it after test rules review.

@missingn0pe missingn0pe added the in-test-rules PR is in our testing suite to collect telemetry label Dec 29, 2025
Added RE/FWD negations & additional conditions for current thread.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant