
Summary
Detects inbound email messages containing a link abusing NSF.org redirect functionality via info.nsf.org/Certified/Sustain/sus_pages.asp, where the ProgramURL query parameter points to a domain other than nsf.org. The rule triggers when a link in the message uses the NSF redirect and the target is external. It excludes messages from nsf.org senders or highly trusted senders if their DMARC authentication passes to reduce false positives. It relies on URL-level analysis of the href_url and its query parameters and on header DMARC evaluation to filter legitimate NSF communications. The detection is categorized under Credential Phishing with the Open Redirect technique and uses URL analysis and header analysis as the primary methods.
Categories
- Web
- Endpoint
Data Sources
- Web Credential
- Domain Name
Created: 2026-10-09