Skip to content

Add detection rule for .reg file attachments#3892

Open
peterdj45 wants to merge 6 commits intomainfrom
peter.new.attachment_reg_file
Open

Add detection rule for .reg file attachments#3892
peterdj45 wants to merge 6 commits intomainfrom
peter.new.attachment_reg_file

Conversation

@peterdj45
Copy link
Copy Markdown
Member

Description

This rule detects messages containing Windows Registry (.reg) files as attachments or within compressed archives.

Associated samples

Associated hunts

This rule detects messages containing Windows Registry (.reg) files as attachments or within compressed archives, highlighting potential security risks.
@peterdj45 peterdj45 requested a review from a team as a code owner February 4, 2026 18:58
@peterdj45 peterdj45 requested a review from a team February 4, 2026 18:58
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Feb 4, 2026
github-actions Bot added a commit that referenced this pull request Feb 4, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request Apr 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant