
Summary
Detects inbound messages containing PDF attachments that match a YARA signature for a specific blurred credential-phishing lure. The rule targets inbound content, filters for attachments with file_type == "pdf", explodes nested file structures, and checks for YARA matches with the signature name pdf_blurred_cred_phish_lure. If a PDF attachment matches the signature, it raises a medium-severity alert indicating a potential credential-phishing attempt using a blurred document lure. The detection combines file analysis with YARA signature matching to identify targeted phishing content in inbound messages.
Categories
- Network
- Endpoint
Data Sources
- File
Created: 2026-10-02