
Summary
This rule detects credential-theft content masquerading as Wufoo emails by analyzing inbound messages sent from no-reply@wufoo.com. It triggers when the message does not present Wufoo in the display name, does not include the expected Wufoo HTML structure (a table with class 'readonly'), contains at least one link, and the current thread text is classified by the embedded NLU model as having a credential-theft intent with non-low confidence. The rule uses content analysis (link presence and text), HTML structure analysis (table pattern), and sender analysis (Wufoo sender verification) to differentiate legitimate Wufoo notifications from abuse. When all conditions are satisfied, the event is flagged as potential Wufoo credential-theft/phishing content for further investigation.
Categories
- Web
- Endpoint
Data Sources
- Web Credential
- Network Traffic
Created: 2026-08-06