
Summary
Analyzes inbound email content to detect replies that reference procurement-tracking codes (e.g., REF-XXXX-XXXX, RF(P|Q|I), BID, PROP patterns) within the message thread. When such reference text is present in embedded links, the rule evaluates the URL to determine the domain of the target and compares it to the sender's domain. If the href URL's root domain differs from the sender's domain, the message is flagged as suspicious. The rule excludes messages from designated high-trust domains if DMARC passes, to reduce false positives. This pattern aligns with lures impersonating procurement or vendor notifications designed to push recipients to external sites. Detections are categorized as Credential Phishing, BEC/Fraud, and Spam, and are supported by detection methods including Content analysis, URL analysis, Header analysis, and Sender analysis. The rule leverages inbound message context and URL-domain relationships to identify social-engineering and impersonation tactics used in phishing attempts aimed at recipients and organizations.
Categories
- Endpoint
- Web
- Application
- Network
- Identity Management
Data Sources
- Application Log
- Network Traffic
- Domain Name
Created: 2026-08-26