Link: Possible Intuit link abuse
Detects messages linking to Intuit notification domains from non-Intuit senders, combined with credential harvesting language and file sharing themes
Sublime rule (View on GitHub)
1name: "Link: Possible Intuit link abuse"
2description: "Detects messages linking to Intuit notification domains from non-Intuit senders, combined with credential harvesting language and file sharing themes"
3type: "rule"
4severity: "medium"
5source: |
6 type.inbound
7 // look for links to links.notification.intuit.com but the sender is not from quickbooks/intuit
8 and any(body.current_thread.links,
9 .href_url.domain.domain == "links.notification.intuit.com"
10 )
11 and not sender.email.domain.root_domain in ("quickbooks.com", "intuit.com")
12 and not any(headers.domains, .root_domain in ("quickbooks.com", "intuit.com"))
13 and length(body.current_thread.text) < 1750
14tags:
15 - "Attack surface reduction"
16attack_types:
17 - "Credential Phishing"
18tactics_and_techniques:
19 - "Impersonation: Brand"
20 - "Social engineering"
21detection_methods:
22 - "URL analysis"
23 - "Natural Language Understanding"
24 - "Content analysis"
25 - "Header analysis"
26id: "cd15cc34-76b3-5993-bade-053e05b2ad48"