Attachment: ICS link with valueless base64 query parameter

Detects inbound emails containing ICS calendar attachments where embedded event links include a randomized 8-character base64 query parameter with no assigned value. The rule excludes messages from high-trust sender domains that pass DMARC authentication.

Sublime rule (View on GitHub)

 1name: "Attachment: ICS link with valueless base64 query parameter"
 2description: "Detects inbound emails containing ICS calendar attachments where embedded event links include a randomized 8-character base64 query parameter with no assigned value. The rule excludes messages from high-trust sender domains that pass DMARC authentication."
 3type: "rule"
 4severity: "medium"
 5source: |
 6  type.inbound
 7  and any(attachments,
 8          (
 9            .file_type == "ics"
10            or .file_extension == "ics"
11            or .content_type in ("application/ics", "text/calendar")
12          )
13          //
14          // This rule makes use of a beta feature and is subject to change without notice
15          // using the beta feature in custom rules is not suggested until it has been formally released
16          //
17          and any(beta.file.parse_ics(.).events,
18                  any(.links,
19                      (
20                        .href_url.path == '/'
21                        and regex.imatch(.href_url.query_params,
22                                         '[A-Za-z0-9+/]{8}'
23                        )
24                        and length(.href_url.query_params_decoded) == 1
25                        and all(flatten(values(.href_url.query_params_decoded)),
26                                . == ''
27                        )
28                      )
29                      or (
30                        ml.link_analysis(., mode="aggressive").effective_url.path == '/'
31                        and regex.imatch(ml.link_analysis(., mode="aggressive").effective_url.query_params,
32                                         '[A-Za-z0-9+/]{8}'
33                        )
34                        and length(ml.link_analysis(., mode="aggressive").effective_url.query_params_decoded
35                        ) == 1
36                        and all(flatten(values(ml.link_analysis(.,
37                                                                mode="aggressive"
38                                               ).effective_url.query_params_decoded
39                                        )
40                                ),
41                                . == ''
42                        )
43                      )
44                      or (
45                        any(ml.link_analysis(., mode="aggressive").final_dom.links,
46                            .href_url.path == '/'
47                            and regex.imatch(.href_url.query_params,
48                                             '[A-Za-z0-9+/]{8}'
49                            )
50                            and length(.href_url.query_params_decoded) == 1
51                            and all(flatten(values(.href_url.query_params_decoded)
52                                    ),
53                                    . == ''
54                            )
55                        )
56                      )
57                  )
58          )
59  )
60  and not (
61    sender.email.domain.root_domain in $high_trust_sender_root_domains
62    and coalesce(headers.auth_summary.dmarc.pass, false)
63  )  
64attack_types:
65  - "ICS Phishing"
66  - "Credential Phishing"
67tactics_and_techniques:
68  - "Evasion"
69  - "Social engineering"
70detection_methods:
71  - "File analysis"
72  - "URL analysis"
73  - "Header analysis"
74id: "d5ce3bc3-9771-541c-a5e5-aedf94cc9e8f"
to-top