heroui logo

Brand impersonation: Deloitte LLC domain in CC

Sublime Rules

View Source
Summary
Technical summary: This inbound email rule flags messages where a recipient in the CC field uses the deloittellc.com root domain, either in the current message or within the body’s previous threads. It evaluates two paths: (1) any CC recipient in the current message with domain.root_domain == 'deloittellc.com', and (2) any CC recipient within any previous_threads embedded in the body whose domain.root_domain == 'deloittellc.com'. When matched, the rule raises a high-severity alert for potential brand impersonation and BEC/fraud, covering scenarios where an attacker leverages Deloitte’s identity to add legitimacy to the message or to hijack an existing discussion thread. The detection method is header analysis (and thread content parsing) to inspect recipient domains in both the message and threaded body content. This rule is geared toward detecting impersonation attempts that exploit Deloitte’s brand, especially in CCs to influence recipients or re-use trusted threads. It does not rely on sender authentication alone but correlates recipient-domain evidence across current and threaded content to identify suspicious impersonation vectors.
Categories
  • Endpoint
Data Sources
  • Domain Name
Created: 2026-09-03