Re: Homoglyph spam/phishing targeting popular brands

2021-02-22 Thread Ricky Boone
On Sun, Feb 14, 2021 at 4:45 PM John Hardin wrote: > > I've added FUZZY rules for amazon, apple, microsoft, facebook, paypal and > norton to my sandbox, they are likely going to be fairly commonB. Looks like the FUZZY_PAYPAL rule may need word boundaries added to the regex. I'm seeing it catch

Re: CHAOS Module Released

2021-02-22 Thread Benny Pedersen
On 2021-02-22 16:00, Alex wrote: Would someone summarize the status of sendgrid right now? If it's not the case sendgrid is categorically just being marked, can we include the domain or email address in the rule description to make it more clear? can sendgrid stop dkim sign all mails ? dkim

Re: Catch subtly-different Reply-To domain

2021-02-22 Thread Dominic Raferd
On 22/02/2021 15:05, RW wrote: On Sun, 21 Feb 2021 16:32:01 -0800 (PST) John Hardin wrote: On Sun, 21 Feb 2021, John Hardin wrote: On Sun, 21 Feb 2021, Dominic Raferd wrote: Michael's suggestion is interesting. There is a github project allowing Levenshtein numbers to be calculated and

Re: Catch subtly-different Reply-To domain

2021-02-22 Thread John Hardin
On Mon, 22 Feb 2021, RW wrote: On Sun, 21 Feb 2021 16:32:01 -0800 (PST) John Hardin wrote: On Sun, 21 Feb 2021, John Hardin wrote: On Sun, 21 Feb 2021, Dominic Raferd wrote: Michael's suggestion is interesting. There is a github project allowing Levenshtein numbers to be calculated and

Re: Catch subtly-different Reply-To domain

2021-02-22 Thread RW
On Sun, 21 Feb 2021 16:32:01 -0800 (PST) John Hardin wrote: > On Sun, 21 Feb 2021, John Hardin wrote: > > > On Sun, 21 Feb 2021, Dominic Raferd wrote: > >> Michael's suggestion is interesting. There is a github project > >> allowing Levenshtein numbers to be calculated and used in SA, I > >>

Re: CHAOS Module Released

2021-02-22 Thread Alex
> >Hope this is useful. Good enough for Noobs, but interesting enough > >for Pros; a little module with a whole lot of 'tude! > >Standard boilerplate introduction: > > looks useful, however, seems that you made checking rules (great) > and mixed them with automatic scoring. > > I'd prefer

Re: CHAOS Module Released

2021-02-22 Thread Matus UHLAR - fantomas
On 10.02.21 07:58, Jared Hall wrote: Hope this is useful.  Good enough for Noobs, but interesting enough for Pros; a little module with a whole lot of 'tude! Standard boilerplate introduction: looks useful, however, seems that you made checking rules (great) and mixed them with automatic