Skip to content

Commit 39000c7

Browse files
[PR #3050] modified rule: Brand Impersonation: Salesforce
1 parent 54b0aec commit 39000c7

File tree

1 file changed

+11
-6
lines changed

1 file changed

+11
-6
lines changed

detection-rules/3050_brand_impersonation_salesforce.yml

Lines changed: 11 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -13,11 +13,16 @@ source: |
1313
and not (
1414
(
1515
// legitimate domains
16-
sender.email.domain.root_domain in (
17-
"salesforce.com",
18-
"salesforceventures.com",
19-
"tangocard.com", //https://www.tangocard.com/salesforce-partnership
20-
"elevatesalesforce.com" // unrelated but name in domain
16+
(
17+
sender.email.domain.root_domain in (
18+
"salesforce.com",
19+
"salesforceventures.com",
20+
"tangocard.com", // https://www.tangocard.com/salesforce-partnership
21+
"elevatesalesforce.com", // unrelated but name in domain
22+
"salesforceben.com", // salesforce newsletter
23+
"connectwithsal.com" // levenshtein
24+
)
25+
or sender.email.domain.domain in ("salesforce.rxsavingssolutions.com") // unrelated but legit domain
2126
)
2227
and headers.auth_summary.dmarc.pass
2328
)
@@ -59,4 +64,4 @@ detection_methods:
5964
id: "c5f0e666-81f0-5d17-a470-12ab75113631"
6065
og_id: "736dfb87-1f99-5cdb-aefc-392257376f3d"
6166
testing_pr: 3050
62-
testing_sha: 75ff228fd19d964d7633fd94026c146efec4de3f
67+
testing_sha: 4ab18f108393f5bc666bcede56c727bfe331192c

0 commit comments

Comments
 (0)