
Summary
This rule targets inbound attachments that are ICS calendar files and uses a beta ICS parser to inspect calendar events for social-engineering, law-related lures. It flags ICS items whose event summaries or descriptions include legal/court language (e.g., subpoenas, court orders, settlements, litigation documents) and/or contain calls to action such as viewing or reviewing materials. It also looks for presence of links within the ICS that display text like 'view'. The rule requires a combination of calendar content with phishing-like cues (e.g., greetings such as 'Dear counsel' or 'Hi team', references to 'file attached', 'respond', 'review') to trigger. Detection methods rely on file/content analysis and URL/link checks. Overall, it aims to detect ICS calendar-based phishing/BEC attempts that leverage legal-themed invites to coerce recipient action. Note: the rule uses a beta ICS parsing feature and may be subject to change as the feature evolves.
Categories
- Endpoint
Data Sources
- File
Created: 2026-09-19