Skip to content

Create detection rule for HTML hex token comments#4094

Open
IndiaAce wants to merge 3 commits intomainfrom
india.fn.ESC-798.create_hex_token_rule
Open

Create detection rule for HTML hex token comments#4094
IndiaAce wants to merge 3 commits intomainfrom
india.fn.ESC-798.create_hex_token_rule

Conversation

@IndiaAce
Copy link
Member

@IndiaAce IndiaAce commented Mar 2, 2026

Description

Tying this to an FN in the FN queue, but this is something I bumped into in the wild. These hex tokens that almost resemble campaign IDs to track phishing campaigns. I think this could be a good rule on its one, but leaving open for a few days to see if we can iterate.

Associated samples

Associated hunts

@IndiaAce
Copy link
Member Author

IndiaAce commented Mar 4, 2026

no matches yet...

@IndiaAce IndiaAce requested a review from a team as a code owner March 6, 2026 17:37
@IndiaAce IndiaAce requested a review from a team March 6, 2026 17:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant