Files
splunk-security_content/macros/evilginx_phishlets_outlook.yml
2019-10-16 16:38:05 +02:00

5 lines
211 B
YAML

definition: (query=outlook* AND query=login* AND query=account*)
description: This limits the query fields to domains that are associated with evilginx
masquerading as Outlook
name: evilginx_phishlets_outlook