Message Recipients

recipients

#

Description

Message Data Model attribute: recipients

Fields #

NameDescription
bccList of 'bcc' Mailbox objects
ccList of 'cc' Mailbox objects
toList of 'to' Mailbox objects

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
recipients.tolength_compare171 rulesmql
recipients.tolength_compare040 rulesmql
recipients.cclength_compare027 rulesmql
recipients.bcclength_compare024 rulesmql
sender.email.emailcross_field_comparerecipients.to[0].email.email20 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().any_messages_malicious_or_spam14 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().prevalence == new8 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().prevalence in (new, outlier)7 rulesmql
body.linkslength_compare1013 rulesmql
recipients.to[0].email.domain.valideqtrue13 rulesmql
recipients.to[0].email.domain.valideqfalse9 rulesmql
attachmentslength_compare112 rulesmql
body.current_thread.textis_null9 rulesmql
body.current_thread.linkslength_compare06 rulesmql
body.current_thread.linkslength_compare106 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

recipients.bcc (collection)

#

Description

Message Data Model attribute: recipients.bcc

Fields #

NameDescription
display_nameDisplay name
email.domain.root_domainThe root domain, including the TLD
email.local_partLocal-part, i.e. before the @

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
body.current_thread.textlength_compare201 rulemql
type.outboundeqtrue1 rulemql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

recipients.cc (collection)

#

Description

Message Data Model attribute: recipients.cc

Fields #

NameDescription
display_nameDisplay name
email.domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
email.domain.root_domainThe root domain, including the TLD
email.domain.validWhether the domain is valid
email.emailFull email address
email.local_partLocal-part, i.e. before the @

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
recipients.cclength_compare14 rulesmql
body.current_thread.textcontainskindly1 rulemql
type.outboundeqtrue1 rulemql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

recipients.to (collection)

#

Description

Message Data Model attribute: recipients.to

Fields #

NameDescription
display_nameDisplay name
email.domain
email.domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
email.domain.root_domainThe root domain, including the TLD
email.domain.sldSecond-level domain, e.g. 'windows' for the domain 'windows.net'
email.domain.validWhether the domain is valid
email.emailFull email address
email.local_partLocal-part, i.e. before the @

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
recipients.tolength_compare165 rulesmql
recipients.tolength_compare035 rulesmql
recipients.cclength_compare024 rulesmql
recipients.bcclength_compare023 rulesmql
sender.email.emailcross_field_comparerecipients.to[0].email.email20 rulesmql
recipients.to[0].email.domain.valideqtrue14 rulesmql
recipients.to[0].email.domain.valideqfalse9 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().any_messages_malicious_or_spam12 rulesmql
profile.by_sender_emailfunc_callprofile.by_sender_email().prevalence == new8 rulesmql
attachmentslength_compare111 rulesmql
body.current_thread.linkslength_compare06 rulesmql
body.current_thread.linkslength_compare105 rulesmql
recipients.to[0].email.emailcross_field_comparesender.email.email6 rulesmql
body.linkslength_compare155 rulesmql
body.linkslength_compare14 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #