Message Body

body

#

Description

Message Data Model attribute: body

Fields #

NameDescription
html
ipsIP Addresses located in the body
linksAll links found in the body of the message, unique by the target and display text/url.
previous_threadsThe previous texts threads of the message'

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type.inboundeqtrue548 rulesmql
profile.by_senderfunc_callprofile.by_sender().any_messages_malicious_or_spam96 rulesmql
profile.by_senderfunc_callprofile.by_sender().prevalence in (new, outlier)30 rulesmql
body.linkslength_compare085 rulesmql
body.linkslength_compare1050 rulesmql
body.linkslength_compare1512 rulesmql
attachmentslength_compare049 rulesmql
attachmentslength_compare111 rulesmql
recipients.tolength_compare136 rulesmql
recipients.tolength_compare027 rulesmql
headers.referenceslength_compare027 rulesmql
headers.in_reply_tois_null26 rulesmql
body.previous_threadslength_compare023 rulesmql
recipients.cclength_compare014 rulesmql
recipients.bcclength_compare013 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

body.current_thread

#

Description

Message Data Model attribute: body.current_thread

Fields #

NameDescription
bannersAll warning banners found in the body of the message.
banners[].textThe text content from the warning banner.
linksAll links found in the given thread, unique by the target and display text/url.
links[].display_textThe text of a hyperlink, if it's not a URL
links[].display_url.domain.root_domainThe root domain, including the TLD
links[].display_url.domain.sldSecond-level domain, e.g. 'windows' for the domain 'windows.net'
links[].display_url.domain.subdomainSubdomain, e.g. 'drive' for the domain 'drive.google.com'
links[].display_url.pathEverything after the TLD and before the query parameters
links[].display_url.urlFull URL
links[].href_url.domain
links[].href_url.domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
links[].href_url.domain.root_domainThe root domain, including the TLD
links[].href_url.domain.sldSecond-level domain, e.g. 'windows' for the domain 'windows.net'
links[].href_url.domain.subdomainSubdomain, e.g. 'drive' for the domain 'drive.google.com'
links[].href_url.domain.tldThe domain's top-level domain. E.g. the TLD of google.com is 'com'
links[].href_url.domain.validWhether the domain is valid
links[].href_url.fragmentFragment identifier; the text following the # in the URL (also called the anchor tag)
links[].href_url.pathEverything after the TLD and before the query parameters
links[].href_url.query_paramsThe full query parameters of the URL
links[].href_url.query_params_decodedThe decoded query parameters of the URL
links[].href_url.query_params_decoded['action'][]
links[].href_url.query_params_decoded['domain']
links[].href_url.query_params_decoded['domain'][]
links[].href_url.query_params_decoded['url']
links[].href_url.rewrite.encodersList of detected URL rewrite encoders while unraveling the URL
links[].href_url.rewrite.originalOriginal URL without any unraveling URL rewrites
links[].href_url.schemeProtocol for the URL request, e.g. http
links[].href_url.urlFull URL
links[].mismatchedWhether the display URL and href URL root domains are mismatched (i.e. .href_url.domain.root_domain != .display_url.domain.root_domain, where both are not null and valid domains)
links[].parserThe parser that was used to derived the link
links[].visibleWhether the link is visible to a human when previewing an email or page
preambleThe preamble text from the thread, typically the headers of a reply or forward. Things like From, Sent, Subject, saved as one big multiline string. This doesn't include banners.
textThe text content from the latest reply/forward in a message thread. This typically excludes content from forwarded messages and warning banners.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type.inboundeqtrue480 rulesmql
type.outboundeqtrue159 rulesmql
profile.by_senderfunc_callprofile.by_sender().any_messages_malicious_or_spam72 rulesmql
attachmentslength_compare065 rulesmql
body.linkslength_compare050 rulesmql
body.linkslength_compare1021 rulesmql
recipients.tolength_compare143 rulesmql
recipients.tolength_compare031 rulesmql
headers.referenceslength_compare037 rulesmql
headers.in_reply_tois_null36 rulesmql
body.current_thread.textcontainssubscription23 rulesmql
body.current_thread.textcontainsinvoice21 rulesmql
body.current_thread.textcontainstransaction21 rulesmql
body.current_thread.textcontainsantivirus20 rulesmql
headers.reply_tolength_compare022 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

body.html

#

Description

Message Data Model attribute: body.html

Fields #

NameDescription
display_textVisible text of the HTML document, with invisible characters removed and non-ASCII characters converted to ASCII spaces.
inner_textInner text of the HTML document that doesn't include HTML tags.
rawDecoded raw content of a body text type (text/[subtype] section)

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
body.html.rawis_null6 rulesmql
body.html.inner_textcontains+14 rulesmql
body.html.inner_textcontainsantivirus4 rulesmql
body.html.inner_textcontainsbtc4 rulesmql
body.html.inner_textcontainscall4 rulesmql
body.html.inner_textcontainscancel4 rulesmql
body.html.inner_textcontainsdetected unusual transactions4 rulesmql
body.html.inner_textcontainsdone by you4 rulesmql
body.html.inner_textcontainsfraud alert4 rulesmql
body.html.inner_textcontainsfruad alert4 rulesmql
body.html.inner_textcontainsget in touch with our4 rulesmql
body.html.inner_textcontainsinvoice4 rulesmql
body.html.inner_textregex_match\+𝟭|𝗽𝗮𝘆𝗺𝗲𝗻𝘁|𝗛𝗲𝗹𝗽 𝗗𝗲𝘀𝗸|𝗿𝗲𝗳𝘂𝗻𝗱|𝗮𝗻𝘁𝗶𝘃𝗶𝗿𝘂𝘀|𝗰𝗮𝗹𝗹|𝗰𝗮𝗻𝗰𝗲𝗹5 rulesmql
body.current_thread.textlength_compare5004 rulesmql
body.current_thread.textregex_matchnote from.{0,50}(?:call|reach|contact|paypal)4 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

body.ips (collection)

#

Description

Message Data Model attribute: body.ips

Fields #

NameDescription
ipThe IP in canonical form

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

body.links (collection)

#

body.plain

#

Description

Message Data Model attribute: body.plain

Fields #

NameDescription
rawDecoded raw content of a body text type (text/[subtype] section)

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
body.plain.rawis_null3 rulesmql
body.plain.rawregex_match[\x{1F300}-\x{1F5FF}\x{1F600}-\x{1F64F}\x{1F680}-\x{1F6FF}\x{1F700}-\x{1F77F}\x{1F780}-\x{1F7FF}\x{1F900}-\x{1F9FF}\x{2600}-\x{26FF}\x{2700}-\x{27BF}\x{2300}-\x{23FF}]4 rulesmql
subject.subjectregex_match[\x{1F300}-\x{1F5FF}\x{1F600}-\x{1F64F}\x{1F680}-\x{1F6FF}\x{1F700}-\x{1F77F}\x{1F780}-\x{1F7FF}\x{1F900}-\x{1F9FF}\x{2600}-\x{26FF}\x{2700}-\x{27BF}\x{2300}-\x{23FF}]3 rulesmql
beta.ocr(file.message_screenshot()).textcontainsreceived a document2 rulesmql
beta.ocr(file.message_screenshot()).textcontainsshared a document2 rulesmql
beta.ocr(file.message_screenshot()).textcontainsshared a file with you2 rulesmql
beta.ocr(file.message_screenshot()).textcontainsshared this document2 rulesmql
beta.ocr(file.message_screenshot()).textcontainsshared with you2 rulesmql
body.html.rawregex_match(background-color:|background:|bgcolor=)(.)?#(00a4ef|0078d7|8bb737|04a5f0|059EE4|05A6F0)2 rulesmql
body.html.rawregex_match(background-color:|background:|bgcolor=)(.)?#(04a1d6|04B5F0|05a1e8|00A4EF|01a4ef|04a5f0)2 rulesmql
body.html.rawregex_match(background-color:|background:|bgcolor=)(.)?#(7cbf42|81bb05|e05c35|7AB206|81BC06)2 rulesmql
body.html.rawregex_match(background-color:|background:|bgcolor=)(.)?#(FFCA07|f7b408|FFB900|FFCA08|ffb901|ffba07)2 rulesmql
body.html.rawregex_match(background-color:|background:|bgcolor=)(.)?#(f65314|f65d35|49a1e8|E74F23|F35325)2 rulesmql
body.html.rawregex_match(background-color:|background:|bgcolor=)(.)?#(ffb900|ffba07|f4bc41|F2B108|FFBA08)2 rulesmql
body.html.rawregex_match(background-color:|background:|bgcolor=)(.)?(#)?(36ba57|3eb55d|7db606|7FBA00|36ba58|green)2 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

body.previous_threads (collection)

#

Description

Message Data Model attribute: body.previous_threads

Fields #

NameDescription
linksAll links found in the given thread, unique by the target and display text/url.
links[].href_url.domain.root_domainThe root domain, including the TLD
links[].href_url.schemeProtocol for the URL request, e.g. http
links[].href_url.urlFull URL
preambleThe preamble text from the thread, typically the headers of a reply or forward. Things like From, Sent, Subject, saved as one big multiline string. This doesn't include banners.
recipients.ccList of 'cc' Mailbox objects
recipients.cc[].email.domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
recipients.toList of 'to' Mailbox objects
recipients.to[].display_nameDisplay name
recipients.to[].email.domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
recipients.to[].email.emailFull email address
sender.display_nameDisplay name
sender.email.domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
sender.email.domain.root_domainThe root domain, including the TLD
sender.email.emailFull email address
subject.baseSubject of the email with tags and reply/forward indicators removed
subject.is_auto_replyIndicates if the subject of the email is an automatic reply
subject.is_forwardIndicates if the subject of the email is a forward
textThe text content from the latest reply/forward in a message thread. This typically excludes content from forwarded messages and warning banners.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
body.previous_threadslength_compare14 rulesmql
filter(flatten([recipients.to, recipients.cc, recipients.bcc]), .email.domain.root_domain in $org_domains)length_compare13 rulesmql
body.previous_threads[].recipients.tolength_compare12 rulesmql
coalesce(body.plain.raw, body.html.display_text)length_compare60002 rulesmql
filter(attachments, .file_type == 'pdf')length_compare01 rulemql
headers.in_reply_tois_not_null1 rulemql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #