Skip to content

Update recon_hotel_booking_reply_to_redirect.yml#3882

Closed
JFarina5 wants to merge 6 commits intomainfrom
JFarina5.FN.6211.hotel.recon
Closed

Update recon_hotel_booking_reply_to_redirect.yml#3882
JFarina5 wants to merge 6 commits intomainfrom
JFarina5.FN.6211.hotel.recon

Conversation

@JFarina5
Copy link
Copy Markdown
Member

@JFarina5 JFarina5 commented Jan 27, 2026

Description

Updating rule to get rid of the reply-to mismatch. Without the reply-to mismatch logic, this rule should gain additional coverage for hotel based recon messages.

Associated samples

Associated hunts

@JFarina5 JFarina5 requested a review from a team as a code owner January 27, 2026 21:29
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Jan 27, 2026
github-actions Bot added a commit that referenced this pull request Jan 28, 2026
Adding the word boundary should get rid of fp matches for legit tools that have a trailing 'suite'
@github-actions github-actions Bot removed the in-test-rules PR is in our testing suite to collect telemetry label Jan 30, 2026
github-actions Bot added a commit that referenced this pull request Jan 30, 2026
github-actions Bot added a commit that referenced this pull request Jan 30, 2026
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Jan 30, 2026
github-actions Bot added a commit that referenced this pull request Jan 30, 2026
github-actions Bot added a commit that referenced this pull request Jan 30, 2026
@JFarina5 JFarina5 requested a review from a team February 2, 2026 21:26
github-actions Bot added a commit that referenced this pull request Feb 2, 2026
@github-actions github-actions Bot added test-rules:excluded:manual Manually excluded from test-rules, either by adding this label or removing the in-test-rules label and removed in-test-rules PR is in our testing suite to collect telemetry labels Feb 2, 2026
github-actions Bot added a commit that referenced this pull request Feb 2, 2026
@aidenmitchell aidenmitchell added in-test-rules PR is in our testing suite to collect telemetry and removed test-rules:excluded:manual Manually excluded from test-rules, either by adding this label or removing the in-test-rules label labels Feb 3, 2026
@JFarina5
Copy link
Copy Markdown
Member Author

JFarina5 commented Mar 3, 2026

This has been sitting for a bit, still getting FPs on this, going to close this PR out and rethink it a bit.

@JFarina5 JFarina5 closed this Mar 3, 2026
github-actions Bot added a commit that referenced this pull request Mar 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants