diff --git a/detection-rules/impersonation_human_resources.yml b/detection-rules/impersonation_human_resources.yml index 9f644239ee2..ebddbd45208 100644 --- a/detection-rules/impersonation_human_resources.yml +++ b/detection-rules/impersonation_human_resources.yml @@ -21,7 +21,7 @@ source: | ) // Negate common marketing mailers and not regex.icontains(sender.display_name, - 'HR (Events|Expert|Support Center|Studies|Knowledge Cloud|News Library|Crowd|Solutions)|HR and People Operations' + 'HR (?:Events|Expert|Support Center|Studies|Knowledge Cloud|News Library|Crowd|Solutions|Interests)|HR and People Operations' ) and not ( any(headers.hops,