
Summary
Detects credential phishing emails that impersonate security alerts from newly registered sender domains (≤90 days old). The rule flags inbound messages where the sender’s domain age is under 90 days and where the subject or body contains typical security alert language (e.g., unusual sign-in or login phrases). It requires at least two of five hallmark indicators within the email body: presence of an IP address, a device indicator, a line stating no action is required, a location field (location:), or a time/date indicator (time:). The intent is to surface social-engineering lures that impersonate account security notices and attempt to harvest credentials or prompt user action. The detection leverages Whois-based domain age checks, content analysis of the email text (regex/substring matching), and sender/domain analysis to identify suspicious origins and phrasing. This rule is particularly aligned with credential phishing campaigns that leverage brand impersonation and security alerts to provoke urgency and credential submission.
Categories
- Network
- Endpoint
Data Sources
- Network Traffic
- Web Credential
Created: 2026-09-18