
Summary
Detection rule for inbound ICS calendar attachments that targets misuse of Unicode tag block characters (U+E0000–U+E007F). These characters render invisibly in many mail clients but map 1:1 to ASCII with an offset, enabling attackers to hide instructions or interleave invisible characters within visible text to defeat content matching. The rule scans inbound content for ICS attachments or calendar content and flags usage in the subject, body, or calendar attachment. It explicitly excludes legitimate flag emoji variants built from tag characters (England, Scotland, Wales). Detection relies on inbound data sources, examining ICS file types or extensions and content types (ICS mime types). It counts occurrences of tag characters (more than 10) and requires either a mixed alphanumeric sequence with embedded tag characters or a long run of tag characters, indicative of smuggling or evasion. This supports defenses against BEC/Fraud and credential phishing by mitigating evasion and social engineering attempts. It employs content, HTML, and header analysis to detect suspicious patterns in email workflows.
Categories
- Endpoint
Data Sources
- File
Created: 2026-10-04