
Summary
This rule detects inbound email messages containing PDF attachments that are characteristic of a Teal SharePoint lure, by applying a YARA rule named pdf_teal_web2pdf to the attachment content. It filters inbound messages to PDF attachments, expands the file contents, and runs a YARA scan. If a match is found, the detection triggers. The rule targets credential phishing attempts that impersonate a SharePoint lure delivered via PDF attachments. Detection methods include file analysis and YARA scanning. Severity is medium, reflecting the potential risk of credential theft via socially engineered PDFs.
Categories
- Network
- Endpoint
Data Sources
- File
Created: 2026-10-05