Files
splunk-security_content/macros/deprecated/evilginx_phishlets_google.yml
2025-12-22 14:01:09 +01:00

5 lines
204 B
YAML

definition: (query=accounts* AND query=ssl* AND query=www*)
description: This limits the query fields to domains that are associated with evilginx
masquerading as Google
name: evilginx_phishlets_google