
Summary
Detects inbound emails where the subject line or sender display name contains 10 or more invisible Unicode characters (e.g., zero-width spaces, soft hyphens, zero-width joiners, BOM) in messages that also contain links or attachments. This obfuscation technique is commonly used to bypass text-based detectors. The rule excludes messages from highly trusted sender domains that pass DMARC authentication to reduce false positives. It relies on counting problematic characters via an icount on the character class [\x{200B}-\x{200F}\x{00AD}\x{FEFF}\x{2060}] in subject and sender fields and triggers when the count is >= 10, combined with either body links or attachments existing. The DMARC condition ensures trusted domains are ignored only if DMARC passes; otherwise, such messages may be flagged. Detection methods include content analysis (message content) and header analysis (DMARC/auth headers).
Categories
- Application
Data Sources
- Application Log
- Network Traffic
Created: 2026-10-09