Skip to content

Create link_suspicious_action_undisclosed_recipients.yml#4240

Open
MSAdministrator wants to merge 2 commits intomainfrom
msadministrator.fn.esc-9106.link_sus_action
Open

Create link_suspicious_action_undisclosed_recipients.yml#4240
MSAdministrator wants to merge 2 commits intomainfrom
msadministrator.fn.esc-9106.link_sus_action

Conversation

@MSAdministrator
Copy link
Member

Description

During a runner ping, it was identified that we didn't flag on a message using mimecastprotect. This is to add coverage for these suspicious links no matter the url is encoded or not.

Associated samples

Associated hunts

@MSAdministrator MSAdministrator requested a review from a team March 20, 2026 19:35
@MSAdministrator MSAdministrator requested a review from a team as a code owner March 20, 2026 19:35
@github-actions github-actions bot added the in-test-rules PR is in our testing suite to collect telemetry label Mar 20, 2026
github-actions bot added a commit that referenced this pull request Mar 20, 2026
github-actions bot added a commit that referenced this pull request Mar 20, 2026
…ction language with undisclosed recipients
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant