Skip to content

Create link_susp_tld_hosting_clientjs.yml - #5245

Open
keaton-sublime wants to merge 5 commits into
mainfrom
keaton-sublime.FN.ESC-23989.susp_tld_cf_beacon
Open

Create link_susp_tld_hosting_clientjs.yml#5245
keaton-sublime wants to merge 5 commits into
mainfrom
keaton-sublime.FN.ESC-23989.susp_tld_cf_beacon

Conversation

@keaton-sublime

@keaton-sublime keaton-sublime commented Sep 2, 2026

Copy link
Copy Markdown
Member

Description

Matching messages with links that resolve to suspicious TLDs and load the CF beaon.js script, while hosting a client.js file locally to that suspicious TLD host.

Associated samples

Associated hunts

@keaton-sublime keaton-sublime added the in-test-rules PR is in our testing suite to collect telemetry label Sep 2, 2026
@github-actions github-actions Bot added hunting-required Hunts needed to validate rule efficacy test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules labels Sep 2, 2026
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Test Rules Sync - Excluded

This PR contains rules that use ml.link_analysis, which is not supported in the test-rules environment.

The hunting-required label has been applied. These rules will need to be tested through alternative methods.

@github-actions github-actions Bot removed the in-test-rules PR is in our testing suite to collect telemetry label Sep 2, 2026
github-actions Bot added a commit that referenced this pull request Sep 2, 2026
@keaton-sublime keaton-sublime added the review-needed Indicates that a PR is waiting for review label Sep 9, 2026
@keaton-sublime

Copy link
Copy Markdown
Member Author

marking review needed/ready for review - the telemetry on this has been very light, but multi-hunts have not shown FPs.

@keaton-sublime
keaton-sublime marked this pull request as ready for review September 9, 2026 17:13
@keaton-sublime
keaton-sublime requested a review from a team September 9, 2026 17:13
@keaton-sublime
keaton-sublime requested a review from a team as a code owner September 9, 2026 17:13
github-actions Bot added a commit that referenced this pull request Sep 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

hunting-required Hunts needed to validate rule efficacy review-needed Indicates that a PR is waiting for review test-rules:excluded:link_analysis Link analysis in rule, excluding from test rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant