Skip to content

Conversation

@aidenmitchell
Copy link
Member

@aidenmitchell aidenmitchell commented Nov 21, 2025

Description

Detects messages containing credential theft language combined with social engineering topics like secure messages, notifications, or authentication alerts. The rule specifically identifies emails that deceptively claim to be from a 'safe sender' or contain 'safe content' in the first line, which is a common tactic used to bypass security filters and gain user trust.

A re-attempt of #2735

Associated samples

@aidenmitchell aidenmitchell requested a review from a team as a code owner November 21, 2025 23:57
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Nov 22, 2025
github-actions bot added a commit that referenced this pull request Nov 22, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant