heroui logo

Attachment: Malformed mobileconfig file

Sublime Rules

View Source
Summary
This rule detects inbound emails that carry attachments with a .mobileconfig extension and are missing mandatory Apple configuration profile fields. It inspects the attachment content (via file.parse_text(…).text) and checks for the presence of the plist keys: PayloadType, PayloadVersion, PayloadIdentifier, and PayloadUUID. If none of these keys are found (i.e., the configuration profile is malformed, tampered, or crafted to exploit device configuration changes), the rule fires. The detection relies on File analysis of email attachments and XML/plist analysis of the attachment's content. The intent is to catch evasion attempts where attackers attempt to push incomplete or malicious configuration profiles that could alter device enrollment, network/VPN settings, or other trusted configurations, potentially facilitating credential harvesting or access persistence. The rule is categorized under Credential Phishing and Evasion techniques, signaling a focus on detecting deceptive or manipulated configuration payloads delivered via email.
Categories
  • Endpoint
  • macOS
  • Web
Data Sources
  • File
Created: 2026-09-29