
Summary
Detects inbound messages where the sender name, as identified by an NLP classifier, claims to be Google Authenticator. Flags when the sending domain is not google.com or okta.com and DMARC authentication does not pass, indicating likely impersonation of the Google Authenticator service. The rule uses NLU to extract a sender entity from the message body, analyzes header data (DMARC) to verify authentication, and performs sender-domain checks. It targets potential brand impersonation and credential phishing via spoofed two-factor authentication messages. Detection methods include Natural Language Understanding, Header analysis, and Sender analysis. Attacks: Credential Phishing, BEC/Fraud. Techniques: Impersonation (Brand), Spoofing.
Categories
- Network
Data Sources
- Network Traffic
Created: 2026-10-02