heroui logo

Link: Gmail confidential mode message from new or unsolicited sender

Sublime Rules

View Source
Summary
This rule detects Gmail confidential mode links in inbound messages from first-time or unsolicited senders, focusing on credential phishing risk. It looks for links in email bodies pointing to confidential-mail.google.com with a path that starts with /msg/. The rule combines two signal streams: (1) sender reputation signals (prevalence= new or outlier and unsolicited) and (2) abuse signals (the sender has any malicious or spam messages and no benign messages). A match indicates a potential credential-phishing attempt leveraging Gmail’s confidential mode to bypass content screening. The rule is labeled as low severity and targets evasion and social engineering tactics, using sender analysis and URL analysis as detection methods. It is categorized under attack surface reduction. False positives may arise from legitimate new senders who legitimately use Gmail confidential mode; exclusions should be maintained to avoid repeated matches on benign messages. The rule complements broader phishing defenses by flagging risky first/unsolicited Gmail confidential mode links rather than content that can be scanned post-authentication. Potential improvements include refining sender exclusions, expanding domain coverage to other confidential-mode link hosts, and correlating with DMARC/DKIM/ SPF results and user-reporting to reduce false positives while maintaining visibility into high-risk messages.
Categories
  • Web
Data Sources
  • Network Traffic
  • Web Credential
Created: 2026-10-07