
Link: Credential theft via newly registered suspicious domain in query parameter
Sublime Rules
View SourceSummary
This rule detects inbound messages where the natural language understanding (NLU) classifier identifies credential-theft intent in the message body and a link within the message contains a query parameter that decodes to a URL whose top-level domain (TLD) is considered suspicious. The domain must have been registered within the last 30 days. The rule excludes messages from high-trust sender domains that pass DMARC authentication to reduce false positives. Detection relies on: (1) NLU to identify the cred_theft intent with non-low confidence, (2) URL analysis to extract and decode query parameters and parse the resulting URLs, (3) Whois/age checks to confirm recent domain registration (days_old < 30), and (4) sender-domain trust evaluation to bypass trusted sources. The tactic/technique mapping includes social engineering and potential open-redirect behavior, while the attack type is Credential Phishing. Data sources cover web credential data, network traffic related to links, and inbound message content for DMARC status. This rule is designed to catch credential harvesting campaigns that rely on newly registered, suspicious domains embedded in phishing links within inbound messages, while minimizing noise from trusted senders.
Categories
- Web
- Network
- Endpoint
Data Sources
- Web Credential
- Network Traffic
- Application Log
Created: 2026-10-10