
Summary
This rule detects inbound messages that include links hosted on monday.com with suspicious intent. It constrains links to subdomains forms and view under monday.com and excludes mailto and plain-text links. It also discards benign form requests by filtering out matches that contain keywords like questionnaire, quote, request, or work order in the final DOM. The detection relies on ML-based analysis of the email body to identify high-confidence social-engineering topics such as Secure Message, E-Signature, and File Sharing and Cloud Services. When the File Sharing topic is present with a high-confidence cred_theft intent, the rule triggers. Additionally, it filters for cases where the message may resemble credential-related lure rather than legitimate content by combining topic and intent signals. The rule negates legitimate replies or forwards by requiring that the message is not a reply/forward with prior thread history. The overall classification targets Credential Phishing and BEC/Fraud, anchored in Social Engineering techniques, with supporting detection methods focused on Natural Language Understanding, URL analysis, and header analysis.
Categories
- Network
- Endpoint
Data Sources
- Script
Created: 2026-10-07