Brand Impersonation: SiriusXM
Impersonation of the broadcasting corporation SiriusXM.
Sublime rule (View on GitHub)
1name: "Brand Impersonation: SiriusXM"
2description: "Impersonation of the broadcasting corporation SiriusXM."
3type: "rule"
4severity: "medium"
5source: |
6 type.inbound
7 and (
8 strings.ilike(sender.display_name, '*siriusxm*')
9 or strings.ilevenshtein(sender.display_name, 'siriusxm') <= 1
10 or strings.ilike(sender.email.domain.domain, '*siriusxm*')
11 )
12 and (
13 sender.email.domain.root_domain not in (
14 'siriusxm.com',
15 'siriusxmmedia.com',
16 'siriusxm.ca',
17 'engagement360.net' // SiriusXM survey vendor
18 )
19 or (
20 sender.email.domain.root_domain in (
21 'siriusxm.com',
22 'siriusxmmedia.com',
23 'siriusxm.ca',
24 'engagement360.net' // SiriusXM survey vendor
25 )
26 and not headers.auth_summary.dmarc.pass
27 )
28 )
29 and not profile.by_sender().solicited
30attack_types:
31 - "Callback Phishing"
32 - "Credential Phishing"
33 - "Spam"
34tactics_and_techniques:
35 - "Free email provider"
36 - "Impersonation: Brand"
37 - "Social engineering"
38detection_methods:
39 - "Content analysis"
40 - "Header analysis"
41 - "Sender analysis"
42id: "70eb3792-cd7a-5369-b1c3-65a3b772de00"