Truth Social infrastructure abuse via link redirect

Email contains a Truth Social link (links.truthsocial.com) but does not originate from a Truth Social domain. This is a known malicious tactic.

Sublime rule (View on GitHub)

 1name: "Truth Social infrastructure abuse via link redirect"
 2description: "Email contains a Truth Social link (links.truthsocial.com) but does not originate from a Truth Social domain. This is a known malicious tactic."
 3type: "rule"
 4severity: "medium"
 5source: |
 6  type.inbound
 7  and length(body.links) < 10
 8  and any(body.links, .href_url.domain.domain == "links.truthsocial.com")
 9  and sender.email.domain.domain not in~ ('truthsocial.com')
10  and (
11    not profile.by_sender().solicited
12    or (
13      profile.by_sender().any_messages_malicious_or_spam
14      and not profile.by_sender().any_messages_benign
15    )
16  )
17  // negate highly trusted sender domains unless they fail DMARC authentication
18  and not (
19    sender.email.domain.root_domain in $high_trust_sender_root_domains
20    and coalesce(headers.auth_summary.dmarc.pass, false)
21  )  
22
23attack_types:
24  - "Credential Phishing"
25  - "Malware/Ransomware"
26  - "Spam"
27tactics_and_techniques:
28  - "Evasion"
29  - "Impersonation: Brand"
30  - "Social engineering"
31detection_methods:
32  - "Content analysis"
33  - "Sender analysis"
34  - "URL analysis"
35id: "aaaa30a8-34f8-57c1-b374-ec7ea15a8dda"
to-top