
Summary
This rule detects credential-phishing attempts that disguise Microsoft authentication pages using a legitimate link redirection/tracking service (soundestlink.com). It targets inbound web content containing links or extracted domain data where the subdomain includes Microsoft-related keywords (microsoft, teams, login, office, 365, outlook) under soundestlink.com. It also accounts for legitimate security service contexts (mimecastprotect.com/mimecast.com) that re-derive the target domain from query parameters and still resolve to a soundestlink.com subdomain with the same keywords. Additionally, it analyzes unparsed content by inspecting HTML display text for mentions of soundestlink.com and extracting domains to verify Microsoft-keyword subdomains exist. The rule uses URL analysis, content analysis, and HTML analysis to flag potential credential-theft phishing campaigns that abuse a trusted redirection service to impersonate Microsoft login pages. Severity is medium, and the detection is focused on brand impersonation, lookalike domains, and social engineering vectors.
Categories
- Web
Data Sources
- Script
- Web Credential
Created: 2026-08-18