
Summary
The rule "Link: chatbot.page Platform Abuse" is designed to detect malicious activities on the chatbot.page platform. It identifies instances where various signals suggest an intention to abuse the platform, such as incomplete or misleading contact information and behaviors indicative of phishing. The detection logic examines inbound traffic with specific conditions: only one link is allowed from the domain chatbot.page, and various JSON attributes within the HTML response are analyzed for red flags. If the email signature name in the JSON is 'John Doe', it suggests falsification, while usage of a free service plan implies potential malicious activity. Furthermore, the rule inspects the number of questions posed to the chatbot; a single question with suspicious content or links is also flagged, especially if they trigger phishing detection algorithms through NLU (Natural Language Understanding) and URL analysis. Outcomes include claims of blocked chatbots by administrators, serving as an additional indicator of suspicious activity.
Categories
- Web
- Cloud
- Application
Data Sources
- Web Credential
- Network Traffic
- Application Log
Created: 2025-06-25