
Summary
Detects inbound messages that purport to come from Zoom infrastructure used to share a clip, where the reply-to address domain has no registered WHOIS record. The rule triggers when the inbound email appears to originate from no-reply@zoom.us, the subject begins with 'Clips', and the reply-to domain cannot be resolved via WHOIS. This combination indicates potential spoofing or abuse of a trusted sender infrastructure to deliver a phishing-like payload. The detection relies on sender analysis, header analysis, and a WHOIS lookup on the reply-to domain, leveraging network traffic data and domain-name information to identify suspicious activity while acknowledging possible false positives for legitimate domains with privacy protections or incomplete WHOIS data.
Categories
- Network
Data Sources
- Network Traffic
- Domain Name
Created: 2026-07-18