
Summary
Detects inbound messages with an attachment containing a URL that starts with https://cal.meetergo.com/d, i.e., a Meetergo scheduling link embedded in an attachment. This rule targets social engineering and credential phishing attempts that use a meeting‑booking page to lure users into clicking a link and potentially revealing credentials. It relies on file analysis to explode attachments and URL analysis to inspect URLs within those files, focusing on inbound communications likely to be acted upon by end users.
Categories
- Endpoint
- Web
Data Sources
- File
Created: 2026-10-09