rule bulwark_https_bulwarkblack_com_blackfile_vishing_extortion_identity_defense { meta: author = "Bulwark Black LLC" source = "https://bulwarkblack.com/blackfile-vishing-extortion-identity-defense/" description = "Auto-extracted indicators. Verify before use; not a behavioral detection rule." generated = "2026-08-27T05:23:11Z" tlp = "TLP:CLEAR" indicator_count = "11" strings: $s0 = "company.sharepoint.com" ascii wide nocase // Domains $s1 = "enrollms.com" ascii wide nocase // Domains $s2 = "getsession.org" ascii wide nocase // Domains $s3 = "organization.sharepoint.com" ascii wide nocase // Domains $s4 = "passkeyms.com" ascii wide nocase // Domains $s5 = "setupsso.com" ascii wide nocase // Domains $s6 = "https://company.sharepoint.com/sites/ProductionOps/" ascii wide nocase // URLs $s7 = "https://organization.sharepoint.com/sites/Legal_Archive/" ascii wide nocase // URLs $s8 = "179.43.185.226" ascii wide nocase // IPv4 $s9 = "victim.user@company.com" ascii wide nocase // Email Addresses $s10 = "victim.user@organization.com" ascii wide nocase // Email Addresses condition: any of ($s*) }