Detection rules › Sublime MQL
Service abuse: Monday.com callback scam
Detects callback scam solicitations originating from Monday.com's notification system using natural language understanding to identify fraudulent callback language in the message body.
Threat classification
Sublime's own taxonomy (not MITRE ATT&CK).
| Category | Values |
|---|---|
| Attack types | Callback Phishing |
| Tactics and techniques | Social engineering, Out of band pivot |
Event coverage
| Message attribute |
|---|
| body.current_thread |
| sender.email |
| type |
Rule body MQL
type.inbound
and sender.email.email == "notifications@monday.com"
and any(ml.nlu_classifier(body.current_thread.text).intents,
.name == "callback_scam"
)
Detection logic
Scope: inbound message.
Detects callback scam solicitations originating from Monday.com's notification system using natural language understanding to identify fraudulent callback language in the message body.
- inbound message
- sender.email.email is 'notifications@monday.com'
any of
ml.nlu_classifier(body.current_thread.text).intentswhere:- .name is 'callback_scam'
Inspects: body.current_thread.text, sender.email.email, type.inbound. Sensors: ml.nlu_classifier.
Indicators matched (2)
| Field | Match | Value |
|---|---|---|
sender.email.email | equals | notifications@monday.com |
ml.nlu_classifier(body.current_thread.text).intents[].name | equals | callback_scam |