
Summary
Detects brand impersonation attempts targeting Aconex users in inbound messages. It triggers when either (1) an NLU-based assessment identifies Aconex in the organization or sender with a credential-theft intent that is not of low confidence, or (2) the message text contains Aconex and at least two of the following indicators: a Support Central reference, an automated-generated disclaimer, a Mail Number, or a Reference Number (with appropriate substring/regex checks). Exclusions apply to messages from trusted domains (oracle.com or aconex.com) that pass DMARC, and to messages from other high-trust sender domains if DMARC passes, to reduce false positives. The rule relies on inbound data, combining NLP classification, content and header analysis, and sender-domain checks to detect credential phishing and impersonation attempts while avoiding trusted senders.
Categories
- Identity Management
- Web
- Other
Data Sources
- Web Credential
Created: 2026-10-07