Truth Social infrastructure abuse via link redirect
Email contains a Truth Social link (links.truthsocial.com) but does not originate from a Truth Social domain. This is a known malicious tactic.
Sublime rule (View on GitHub)
1name: "Truth Social infrastructure abuse via link redirect"
2description: "Email contains a Truth Social link (links.truthsocial.com) but does not originate from a Truth Social domain. This is a known malicious tactic."
3type: "rule"
4severity: "medium"
5source: |
6 type.inbound
7 and length(body.links) < 10
8 and any(body.links, .href_url.domain.domain == "links.truthsocial.com")
9 and sender.email.domain.domain not in~ ('truthsocial.com')
10 and (
11 not profile.by_sender().solicited
12 or (
13 profile.by_sender().any_messages_malicious_or_spam
14 and not profile.by_sender().any_messages_benign
15 )
16 )
17 // negate highly trusted sender domains unless they fail DMARC authentication
18 and not (
19 sender.email.domain.root_domain in $high_trust_sender_root_domains
20 and coalesce(headers.auth_summary.dmarc.pass, false)
21 )
22
23attack_types:
24 - "Credential Phishing"
25 - "Malware/Ransomware"
26 - "Spam"
27tactics_and_techniques:
28 - "Evasion"
29 - "Impersonation: Brand"
30 - "Social engineering"
31detection_methods:
32 - "Content analysis"
33 - "Sender analysis"
34 - "URL analysis"
35id: "aaaa30a8-34f8-57c1-b374-ec7ea15a8dda"