
Summary
This rule targets inbound emails that contain links exploiting an open redirect vulnerability on toradex.com's /service/share endpoint. It triggers when a link in the email body points to toradex.com, the path includes /service/share, and the URL contains both target and url query parameters that would initiate a redirect. To reduce noise, it excludes redirects where the destination URL is still within toradex.com (i.e., the url parameter points back to the same domain). The detection relies on URL analysis within inbound content (type.inbound, analyzing body.links) and flags activity as a potential credential phishing vector that uses open redirects to lure users to attacker-controlled destinations while appearing to originate from a trusted domain. The rule is specific to this vendor/endpoint and may not generalize to other open redirects without adjustment. It is designed to be used in email security analytics or gateway rules to surface suspicious redirect patterns before users click through. Potential limitations include handling obfuscated or canonicalized URLs and missing redirects on other endpoints or domains without modification.
Categories
- Web
- Endpoint
Data Sources
- Network Traffic
Created: 2026-10-05