
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
Sublime Rules
View SourceSummary
This detection rule identifies suspicious Request for Quote (RFQ) or Request for Proposal (RFP) communications that may indicate fraudulent activity or scams. The rule checks for specific patterns in the sender and recipient lists, attachment types, and the content of the email body. Key indicators of a potential scam include the use of free email providers, suspicious reply-to addresses, or abnormal recipient patterns, such as 'Undisclosed recipients'. The rule also uses natural language processing techniques to identify RFQ/RFP related phrases, enhancing the detection of potentially malicious intents. Additionally, it analyzes whether attachments meet certain criteria related to RFQ/RFP discussions. By compiling these factors, the rule aims to prevent financial losses related to scams where recipients are misled into providing sensitive information or engaging in unauthorized transactions.
Categories
- Web
- Endpoint
- Cloud
- Application
Data Sources
- User Account
- Web Credential
- Network Traffic
- Application Log
Created: 2023-06-26