
Summary
This rule flags Gmail confidential mode messages that exhibit suspicious recipient patterns, specifically when the sender is the only recipient or when there are no valid recipients. The detection triggers on inbound content that references a Gmail confidential mode URL (confidential-mail.google.com) with a path starting at /msg/, combined with a recipient set that matches either a self-sent pattern (to includes only the sender) or a scenario with no valid To recipients (and not exactly one valid CC). The intent is to catch actor-controlled content delivered in a way that can evade automated content scanning, using Gmail’s Confidential Mode as a delivery vector. Detection relies on: inbound source; URL analysis to identify confidential-mail.google.com links with /msg/ paths; and recipient analysis to determine self-sent or invalid recipient configurations. The rule is categorized as a low-severity evasion/credential-phishing pattern and should be used at gateways or endpoints with access to inbound mail content. False positives may occur for legitimate users who routinely email themselves or use atypical recipient patterns, hence the recommendation to employ sender exclusions or corroborating signals before triggering remediation. Sensible deployment guidance includes combining with additional anomaly signals (e.g., unusual sending patterns, frequency, or other Gmail Confidential Mode indicators) to reduce noise while preserving visibility into potential abuse of confidential delivery features.
Categories
- Web
- Network
- Endpoint
Data Sources
- Network Traffic
Created: 2026-10-07