Skip to content

Create detection rule for BEC tax document requests#4586

Open
cybher0808 wants to merge 5 commits into
mainfrom
cybher0808.fn.esc-14468.bectax
Open

Create detection rule for BEC tax document requests#4586
cybher0808 wants to merge 5 commits into
mainfrom
cybher0808.fn.esc-14468.bectax

Conversation

@cybher0808

@cybher0808 cybher0808 commented Jun 2, 2026

Copy link
Copy Markdown
Member

Description

Detects messages requesting W-2 tax documents or related tax information. The rule identifies senders using common administrative local parts and filters for messages containing W-2 language combined with request entities detected through natural language processing.

Associated samples

Associated hunts

@cybher0808 cybher0808 requested a review from a team June 2, 2026 01:58
@cybher0808 cybher0808 requested a review from a team as a code owner June 2, 2026 01:58
@cybher0808 cybher0808 self-assigned this Jun 2, 2026
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Jun 2, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request Jun 2, 2026
github-actions Bot added a commit that referenced this pull request Jun 2, 2026
@cybher0808

cybher0808 commented Jun 2, 2026

Copy link
Copy Markdown
Member Author

Results look really good here after sharing results from multi-hunt. Marking R4R.

@cybher0808 cybher0808 added the review-needed Indicates that a PR is waiting for review label Jun 2, 2026
Comment thread detection-rules/tax_w2_impersonation.yml Outdated
Comment thread detection-rules/tax_w2_impersonation.yml Outdated
Comment thread detection-rules/tax_w2_impersonation.yml Outdated
Comment thread detection-rules/tax_w2_impersonation.yml Outdated
@zoomequipd zoomequipd self-assigned this Jun 4, 2026
@cybher0808 cybher0808 removed the review-needed Indicates that a PR is waiting for review label Jun 5, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request Jun 5, 2026
github-actions Bot added a commit that referenced this pull request Jun 5, 2026
github-actions Bot added a commit to IndiaAce/sublime-rules that referenced this pull request Jun 5, 2026
github-actions Bot added a commit that referenced this pull request Jun 5, 2026
@cybher0808

cybher0808 commented Jun 8, 2026

Copy link
Copy Markdown
Member Author

Shared latest mode and ran SS hunt - 180 Days. Added a few changes with the keywords in the body and I noticed there were a few emails with sender domain that was created less than 30 days.

Marking for review.

@cybher0808 cybher0808 added the review-needed Indicates that a PR is waiting for review label Jun 8, 2026
@IndiaAce IndiaAce assigned IndiaAce and unassigned zoomequipd Jun 10, 2026
@IndiaAce IndiaAce self-requested a review June 10, 2026 14:46
Comment thread detection-rules/tax_w2_impersonation.yml
@IndiaAce IndiaAce removed the review-needed Indicates that a PR is waiting for review label Jun 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants