Skip to content

Update paypal_invoice_abuse.yml #2684

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 8 commits into
base: main
Choose a base branch
from
Open

Update paypal_invoice_abuse.yml #2684

wants to merge 8 commits into from

Conversation

zoomequipd
Copy link
Member

@zoomequipd zoomequipd commented May 8, 2025

Description

Complete rewrite of the rule to support use of xpath which allows for elements within the paypal template to be inspected individually. This reduces FP significantly and allows for the removal of subject based "gating" while allowing expanded scope or a list of "or" statements instead of "4 of".

Based on the sample from #2627

Associated samples

  • 29a2db991439cd522045605c043ccf50d2e9612908df705b6a12669e664baea4

Associated hunts

@zoomequipd zoomequipd requested a review from a team as a code owner May 8, 2025 03:28
@zoomequipd
Copy link
Member Author

/mql-mimic-exempt: 835744, 850953, 941732

These are not malicious

@zoomequipd
Copy link
Member Author

/update-test-rules

github-actions bot pushed a commit that referenced this pull request May 8, 2025
Update paypal_invoice_abuse.yml by @zoomequipd
#2684
Source SHA d0742ed
Triggered by @zoomequipd
@zoomequipd zoomequipd added the in-test-rules PR is in our testing suite to collect telemetry label May 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
in-test-rules PR is in our testing suite to collect telemetry
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant