Detection rules › Sublime MQL
Service abuse: Microsoft Power BI callback scam
Detects callback scam content sent from the legitimate Microsoft Power BI service email address, indicating potential service abuse to distribute fraudulent callback solicitations.
Threat classification
Sublime's own taxonomy (not MITRE ATT&CK).
| Category | Values |
|---|---|
| Attack types | Callback Phishing |
| Tactics and techniques | Out of band pivot, Social engineering |
Event coverage
| Message attribute |
|---|
| body.current_thread |
| sender.email |
| type |
Rule body MQL
type.inbound
and sender.email.email == 'no-reply-powerbi@microsoft.com'
and any(ml.nlu_classifier(body.current_thread.text).intents,
.name == "callback_scam"
)
Detection logic
Scope: inbound message.
Detects callback scam content sent from the legitimate Microsoft Power BI service email address, indicating potential service abuse to distribute fraudulent callback solicitations.
- inbound message
- sender.email.email is 'no-reply-powerbi@microsoft.com'
any of
ml.nlu_classifier(body.current_thread.text).intentswhere:- .name is 'callback_scam'
Inspects: body.current_thread.text, sender.email.email, type.inbound. Sensors: ml.nlu_classifier.
Indicators matched (2)
| Field | Match | Value |
|---|---|---|
sender.email.email | equals | no-reply-powerbi@microsoft.com |
ml.nlu_classifier(body.current_thread.text).intents[].name | equals | callback_scam |