
Summary
This detection rule identifies unsolicited emails that inform recipients about new jobs or roles. Such messages often include links for unsubscribing, scheduling calendar events, or clearly exhibit traits linked to B2B cold outreach. The detection mechanism employs multiple criteria: it checks whether the email is sent directly to a single recipient, looks for specific phrases related to job congratulations in either the subject line or email body, and scans for links that indicate an opt-out or booking feature. Additionally, it utilizes natural language understanding (NLU) to classify messages that denote B2B cold outreach if these are identified in the body of the email. To ensure authenticity, the rule reinforces that the sender has no prior communication history with the recipient, avoiding false positives from known contact patterns.
Categories
- Web
- Endpoint
- Identity Management
Data Sources
- User Account
- Application Log
- Process
Created: 2025-09-30