heroui logo

Impersonation: SAM/SBA federal registration

Sublime Rules

View Source
Summary
Technical summary: The rule detects inbound email impersonation attempts targeting SAM.gov or the Small Business Administration by evaluating two risk paths. First, it matches the sender display_name against spoofed-patterns intended to imitate SAM.gov or SBA entities (e.g., sam.gov variants, SBA-related forms such as renewal/compliance, SBA domains, and common SBA impersonation phrases). Second, it looks for a sam.gov reference within the message body paired with an embedded image lure (an HTML image src containing a sam%20renew%20entity token). Legitimate senders from verified high-trust domains that pass DMARC authentication are excluded. The rule triggers when either spoofed display-name patterns are detected or the combination of a sam.gov reference in the body with a corresponding image lure is found, unless the sender is from a high-trust domain with a DMARC pass. Detection methods include sender analysis, content analysis, HTML analysis, and header analysis. Attacks addressed include Credential Phishing and BEC/Fraud. Tactics include Impersonation: Brand, Social engineering, and Image as content.
Categories
  • Identity Management
  • Web
  • Application
Data Sources
  • Domain Name
Created: 2026-08-13