mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
5 lines
211 B
YAML
5 lines
211 B
YAML
definition: (query=outlook* AND query=login* AND query=account*)
|
|
description: This limits the query fields to domains that are associated with evilginx
|
|
masquerading as Outlook
|
|
name: evilginx_phishlets_outlook
|