Detection rules › Sublime MQL

Brand impersonation: Silicon Valley Bank

Severity
medium
Type
rule
Source
github.com/sublime-security/sublime-rules

Detects emails that impersonate Silicon Valley Bank

Threat classification

Sublime's own taxonomy (not MITRE ATT&CK).

CategoryValues
Attack typesCredential Phishing
Tactics and techniquesImpersonation: Brand, Lookalike domain, Social engineering

Event coverage

Message attribute
sender
sender.email
type

Rule body MQL

type.inbound
and (
  regex.icontains(sender.email.domain.domain,
                  "(silicon(e)?.{0,10}(valley|bank)|svb)"
  )
  or strings.ilevenshtein(sender.display_name, 'svb') <= 1
)
and network.whois(sender.email.domain).days_old <= 30

Detection logic

Scope: inbound message.

Detects emails that impersonate Silicon Valley Bank

  1. inbound message
  2. any of:
    • sender.email.domain.domain matches '(silicon(e)?.{0,10}(valley|bank)|svb)'
    • sender.display_name is similar to 'svb'
  3. network.whois(sender.email.domain).days_old ≤ 30

Inspects: sender.display_name, sender.email.domain, sender.email.domain.domain, type.inbound. Sensors: network.whois, regex.icontains, strings.ilevenshtein.

Indicators matched (2)

FieldMatchValue
regex.icontainsregex(silicon(e)?.{0,10}(valley|bank)|svb)
strings.ilevenshteinfuzzysvb