
Summary
Inbound email content detection for Unicode Tag Block characters (U+E0000–U+E007F). The rule monitors subject, body (HTML inner text), and calendar attachments for usage of tag characters that render invisibly yet map 1:1 to ASCII with an offset (0xE0000). Attackers leverage these characters to smuggle hidden instructions for LLM-powered assistants and to interleave invisible characters within visible text to evade content-matching systems. The rule explicitly excludes the legitimate England, Scotland, and Wales subdivision flag emoji (also formed from tag characters). Detection triggers when there are more than 10 occurrences of tag characters and the content matches either: (a) an alphanumeric around-tag pattern [A-Za-z0-9][\x{E0020}-\x{E007E}]+[A-Za-z0-9], or (b) a run of tags of length 10 or more. This targets inbound messages that may be used for BEC/Fraud and credential phishing via evasion and social engineering. Detection methods include Content analysis, HTML analysis, and Header analysis. The rule is assigned medium severity and is relevant to email-based surface area expansion and phishing threat models, supported by references on ASCII smuggling and Unicode tag usage.
Categories
- Endpoint
- Web
Data Sources
- Process
- File
Created: 2026-10-04