Message Headers

headers (collection)

#

Description

Message Data Model attribute: headers

Fields #

NameDescription
domainsAll domains found in the Received headers
hopsList of hops the message took from Sender to Recipient
in_reply_toIn-Reply-To header value which identifies its parent message if exists
ipsAll IP addresses found in the Received headers
mailerX-Mailer or User-Agent extracted from headers
message_idMessage-ID extracted from the header
referencesThe Message-IDs of the other messages within this chain
references[]The Message-IDs of the other messages within this chain
reply_toWhere replies should be delivered to

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
profile.by_senderfunc_callprofile.by_sender().any_messages_malicious_or_spam58 rulesmql
headers.referenceslength_compare046 rulesmql
headers.in_reply_tois_null45 rulesmql
body.linkslength_compare036 rulesmql
body.linkslength_compare1019 rulesmql
headers.reply_tolength_compare032 rulesmql
recipients.tolength_compare024 rulesmql
recipients.tolength_compare123 rulesmql
headers.auth_summary.dmarc.passeqtrue18 rulesmql
headers.auth_summary.spf.passeqtrue18 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().any_messages_malicious_or_spam14 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().prevalence in (new, outlier)9 rulesmql
recipients.cclength_compare013 rulesmql
body.previous_threadslength_compare012 rulesmql
recipients.bcclength_compare012 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

headers.auth_summary

#

Description

Message Data Model attribute: headers.auth_summary

Fields #

NameDescription
dmarc.details.from.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
dmarc.details.from.root_domainThe root domain, including the TLD
dmarc.passWhether the DMARC check passed
spf.details.designatorEmail or domain of the designating body
spf.passWhether the SPF check passed

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type.inboundeqtrue452 rulesmql
profile.by_senderfunc_callprofile.by_sender().any_messages_malicious_or_spam92 rulesmql
profile.by_senderfunc_callprofile.by_sender().prevalence in (new, outlier)25 rulesmql
attachmentslength_compare044 rulesmql
body.linkslength_compare040 rulesmql
body.linkslength_compare1026 rulesmql
headers.auth_summary.dmarc.passeqtrue36 rulesmql
headers.auth_summary.spf.passeqtrue32 rulesmql
headers.in_reply_tois_null29 rulesmql
headers.referenceslength_compare029 rulesmql
recipients.tolength_compare023 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().any_messages_malicious_or_spam20 rulesmql
headers.reply_tolength_compare016 rulesmql
recipients.cclength_compare014 rulesmql
body.current_thread.textcontainsinvoice13 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

headers.domains (collection)

#

Description

Message Data Model attribute: headers.domains

Fields #

NameDescription
domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
root_domainThe root domain, including the TLD
tldThe domain's top-level domain. E.g. the TLD of google.com is 'com'

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
beta.ocr(file.message_screenshot()).textcontainsreview2 rulesmql
beta.ocr(file.message_screenshot()).textcontainsview2 rulesmql
body.current_thread.textcontainsblocked2 rulesmql
body.current_thread.textcontainsnotification2 rulesmql
body.current_thread.textcontainsprevented2 rulesmql
body.current_thread.textcontainsreview2 rulesmql
body.current_thread.textcontainsserver error2 rulesmql
body.current_thread.textcontainsunsubscribe2 rulesmql
body.current_thread.textcontains2884 sand hill road1 rulemql
body.current_thread.textcontainsmenlo park, ca 940251 rulemql
body.current_thread.textcontainsmessages1 rulemql
body.current_thread.textlength_compare2502 rulesmql
body.current_thread.textlength_compare7002 rulesmql
filter(body.links, .href_url.scheme != 'mailto')length_compare02 rulesmql
sender.display_nameregex_match[a-z0-9]+@[a-z]+2 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

headers.hops (collection)

#

Description

Message Data Model attribute: headers.hops

Fields #

NameDescription
authentication_results.compauth.verdictVerdict of the compauth
authentication_results.dkimVerdict of the Domain Keys Identified Mail check
authentication_results.dkim_detailsList of details of the Domain Keys Identified Mail checks
authentication_results.dkim_details[].domainDomain identified in the DKIM signature if any. This is the domain that's queried for the public key.
authentication_results.dmarcVerdict of the Domain-based Message Authentication, Reporting & Conformance check
authentication_results.dmarc_details.from.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
authentication_results.spfVerdict of the Sender Policy Framework
authentication_results.spf_details.designatorEmail or domain of the designating body
fieldsList of all raw header fields contained within this hop
fields[].nameThe name of the field
fields[].valueThe value contained within the field
indexIndex indicates the order in which a hop occurred from sender to recipient
received.server.rawThe raw string of 'by' section
received.source.rawThe raw string of 'from' section
received_spf.designatorEmail or domain of the designating body
signature.headersHeader fields signed by the algorithm

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
headers.auth_summary.dmarc.passis_null4 rulesmql
coalescefunc_callcoalesce(headers.auth_summary.dmarc.pass)3 rulesmql
ml.nlu_classifier(body.current_thread.text).intentslength_compare03 rulesmql
attachmentslength_compare82 rulesmql
beta.ocr(file.message_screenshot()).textcontainsdocusign2 rulesmql
beta.ocr(file.message_screenshot()).textregex_matchDokument (überprüfen|prüfen|unterschreiben|geschickt)2 rulesmql
beta.ocr(file.message_screenshot()).textregex_matchimportant edocs2 rulesmql
body.current_thread.textcontainsdocument portal2 rulesmql
body.current_thread.textlength_compare1002 rulesmql
body.html.rawregex_match((<br\s*/?>\s*){20,}|\n{20,})2 rulesmql
body.html.rawregex_match(<p class=".*?"><span style=".*?"><o:p>&nbsp;</o:p></span></p>\s*){30,}2 rulesmql
body.html.rawregex_match(<p>&nbsp;</p>\s*){7,}2 rulesmql
body.html.rawregex_match(<p[^>]*>&nbsp;</p>\s*){7,}2 rulesmql
body.html.rawregex_match(<p[^>]*>\s*&nbsp;<br>\s*</p>\s*){5,}2 rulesmql
body.html.rawregex_match(<p[^>]*>\s*<br\s*/?>\s*</p>\s*){30,}2 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

headers.ips (collection)

#

Description

Message Data Model attribute: headers.ips

Fields #

NameDescription
ipThe IP in canonical form

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

headers.reply_to (collection)

#

Description

Message Data Model attribute: headers.reply_to

Fields #

NameDescription
display_nameDisplay name
email.domain
email.domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
email.domain.root_domainThe root domain, including the TLD
email.domain.tldThe domain's top-level domain. E.g. the TLD of google.com is 'com'
email.domain.validWhether the domain is valid
email.emailFull email address
email.local_partLocal-part, i.e. before the @

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
headers.reply_tolength_compare031 rulesmql
headers.auth_summary.dmarc.passeqtrue12 rulesmql
headers.auth_summary.spf.passeqtrue12 rulesmql
beta.profile.by_reply_tofunc_callbeta.profile.by_reply_to().prevalence == new5 rulesmql
network.whoisfunc_callnetwork.whois(sender.email.domain).days_old <= 303 rulesmql
sender.email.domain.root_domaineqdocusign.net3 rulesmql
sender.email.emaileqno-reply@zoom.us3 rulesmql
body.current_thread.textcontains (kindly 2 rulesmql
body.current_thread.textcontains anyone you know 2 rulesmql
body.current_thread.textcontains downsizing 2 rulesmql
body.current_thread.textcontains free donation2 rulesmql
body.current_thread.textcontains generously offering 2 rulesmql
body.current_thread.textcontains if you will take it 2 rulesmql
body.current_thread.textcontains indicate your interest 2 rulesmql
body.current_thread.textcontains kindly 2 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

headers.return_path

#

Description

Message Data Model attribute: headers.return_path

Fields #

NameDescription
domain
domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
domain.root_domainThe root domain, including the TLD
domain.tldThe domain's top-level domain. E.g. the TLD of google.com is 'com'
emailFull email address
local_partLocal-part, i.e. before the @

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
headers.return_path.domain.domaincross_field_comparesender.email.domain.domain2 rulesmql
headers.return_path.domain.domaineqsendgrid.net3 rulesmql
headers.return_path.domain.domainnecalendar-server.bounces.google.com2 rulesmql
headers.auth_summary.spf.details.designatorcontains+srs=2 rulesmql
headers.return_path.domain.root_domaineqsalesforce.com2 rulesmql
headers.return_path.domain.root_domainnebestdeals.today2 rulesmql
headers.return_path.emailcross_field_comparesender.email.email2 rulesmql
headers.return_path.emailis_not_null2 rulesmql
headers.return_path.local_partcontains+srs=2 rulesmql
network.whoisfunc_callnetwork.whois(sender.email.domain).days_old <= 302 rulesmql
sender.email.domain.root_domainnebestdeals.today2 rulesmql
subject.subjectregex_matchremittance2 rulesmql
subject.subjectregex_matchw22 rulesmql
beta.ocr(file.message_screenshot()).textcontainsbest buy1 rulemql
beta.ocr(file.message_screenshot()).textcontainsebay1 rulemql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

headers.x_authenticated_domain

#

Description

Message Data Model attribute: headers.x_authenticated_domain

Fields #

NameDescription
domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

headers.x_authenticated_sender

#

Description

Message Data Model attribute: headers.x_authenticated_sender

Fields #

NameDescription
emailFull email address

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

headers.x_originating_ip

#

Description

Message Data Model attribute: headers.x_originating_ip

Fields #

NameDescription
ipThe IP in canonical form

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
headers.mailerstarts_withOpen-Xchange Mailer1 rulemql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #