Link: Possible Intuit link abuse

Detects messages linking to Intuit notification domains from non-Intuit senders, combined with credential harvesting language and file sharing themes

Sublime rule (View on GitHub)

 1name: "Link: Possible Intuit link abuse"
 2description: "Detects messages linking to Intuit notification domains from non-Intuit senders, combined with credential harvesting language and file sharing themes"
 3type: "rule"
 4severity: "medium"
 5source: |
 6  type.inbound
 7  // look for links to links.notification.intuit.com but the sender is not from quickbooks/intuit
 8  and any(body.current_thread.links,
 9          .href_url.domain.domain == "links.notification.intuit.com"
10  )
11  and not sender.email.domain.root_domain in ("quickbooks.com", "intuit.com")
12  and not any(headers.domains, .root_domain in ("quickbooks.com", "intuit.com"))
13  and length(body.current_thread.text) < 1750  
14tags:
15 - "Attack surface reduction"
16attack_types:
17  - "Credential Phishing"
18tactics_and_techniques:
19  - "Impersonation: Brand"
20  - "Social engineering"
21detection_methods:
22  - "URL analysis"
23  - "Natural Language Understanding"
24  - "Content analysis"
25  - "Header analysis"
26id: "cd15cc34-76b3-5993-bade-053e05b2ad48"

Related rules

to-top