
Summary
This rule identifies spam messages that falsely claim to have detected errors on a website, prompting users to inquire about services or solutions. It employs multiple criteria to trigger detection: if the sender is not in the recipient's email list or is unsolicited by the recipient profile. Key factors for detection include the length and content of the email body, the presence of specific keywords such as 'error', 'report', or 'screenshot', and whether the subject line contains certain terms related to proposals or audits. The rule differentiates between single-thread and multi-thread conversations, checking for specific characteristics like the lack of attachments, the inclusion of an unsubscribe link, and a minimum length of previous threads. The overall goal is to prevent users from falling victim to unsolicited phishing attempts that use faux urgency by citing website errors.
Categories
- Web
- Endpoint
- Cloud
Data Sources
- User Account
- Application Log
- Process
Created: 2025-10-31