
Summary
Inbound rule that flags PDF attachments in messages which trigger a specific YARA signature named pdf_msft_lure_signature, indicative of a Microsoft-themed lure used in credential phishing. The rule activates when the message source is inbound, there is at least one attachment with file_type "pdf", and the scanned attachment content yields a YARA match with the rule name pdf_msft_lure_signature. It relies on file analysis and YARA scanning to identify targeted document-based social engineering attempts intended to steal credentials. Data sources: File (attachment content). Domain coverage: Endpoint (user devices/mail clients) and Web (webmail gateways). Detection methods: YARA and file analysis. Keywords: PDF, YARA, phishing, lure, signature. Attack types/techniques: Credential Phishing; PDF-based lure; Impersonation: Brand; Social engineering. Notes: Ensure the pdf_msft_lure_signature YARA rule is loaded and that attachment analysis can explode nested content if needed. Monitor for false positives with legitimate PDFs and maintain alignment with other anti-phishing controls.
Categories
- Endpoint
- Web
Data Sources
- File
Created: 2026-10-02