Skip to content

Create suspicious_request_account_invoice.yml#4226

Open
cybher0808 wants to merge 5 commits intomainfrom
cybher0808.fn.esc-9018.susinvoice
Open

Create suspicious_request_account_invoice.yml#4226
cybher0808 wants to merge 5 commits intomainfrom
cybher0808.fn.esc-9018.susinvoice

Conversation

@cybher0808
Copy link
Member

@cybher0808 cybher0808 commented Mar 19, 2026

Description

Detects business email compromise attempts using vendor impersonation tactics with financial language focused on invoice payments, account balances, and payment processing requests.

Associated samples

Associated hunts

@cybher0808 cybher0808 requested a review from a team March 19, 2026 00:02
@cybher0808 cybher0808 requested a review from a team as a code owner March 19, 2026 00:02
@cybher0808 cybher0808 self-assigned this Mar 19, 2026
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Mar 19, 2026
github-actions bot added a commit that referenced this pull request Mar 19, 2026
github-actions bot added a commit that referenced this pull request Mar 19, 2026
github-actions bot added a commit that referenced this pull request Mar 19, 2026
github-actions bot added a commit that referenced this pull request Mar 19, 2026
@cybher0808
Copy link
Member Author

May close this PR since I have a better option for this sample in PR 4242

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant