
Summary
This rule detects inbound messages that contain URLs with a subdomain ending in a hyphen, a characteristic used to obscure the true destination or imitate legitimate brands. The detection targets links within the message body (body.links) and ignores mailto links. It leverages URL parsing to examine the href_url.domain.subdomain component and triggers when the subdomain ends with a hyphen, which violates RFC 952 hostname rules and is commonly used in social engineering campaigns such as fake NDAs, confidential annexes, or missed voicemail notifications. The technique supports defense against credential phishing by reducing the attack surface when recipients encounter suspicious links disguised as trusted services. The rule is categorized under social engineering, lookalike domain impersonation, and brand impersonation, and employs URL analysis and content analysis as its primary detection methods.
Categories
- Endpoint
Data Sources
- Application Log
Created: 2026-10-06