
Summary
The rule detects inbound email messages that purport to come from Apple's noreply address but show spoofing indicators in header data and content. It requires: 1) the sender.email equals noreply@email.apple.com; 2) any reply-to header whose root domain is not apple.com; 3) a Natural Language Understanding (NLU) classifier applied to the message body that identifies intent labeled 'callback_scam' with a confidence that is not 'low' (i.e., medium or high). When all conditions are met, the rule triggers for medium severity, classifying this as a Callback Phishing attempt involving social engineering and potential out-of-band pivot. This approach combines sender and header analysis with NLP to detect nuanced phishing attempts that rely on legitimate branding to provoke a callback.
Categories
- Endpoint
- Network
Data Sources
- Network Traffic
Created: 2026-09-30