Message Sender

Attribute groupRule
senderY
sender.emailY

sender

#

Description

Message Data Model attribute: sender

Fields #

NameDescription
display_nameDisplay name

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
headers.reply_tolength_compare012 rulesmql
beta.ocrfunc_callbeta.ocr(file.message_screenshot()).text != 7 rulesmql
subject.subjectregex_matchtermination.*notice7 rulesmql
subject.subjectregex_match384176 rulesmql
subject.subjectregex_match:completed6 rulesmql
subject.subjectregex_match[il1]{2}mit.*ma[il1]{2} ?bo?x6 rulesmql
subject.subjectregex_match[il][il][il]egai[ -]6 rulesmql
subject.subjectregex_match[li][li][li]ega[li] attempt6 rulesmql
subject.subjectregex_match[ng]-?[io]n .*block6 rulesmql
subject.subjectregex_match[ng]-?[io]n .*cancel6 rulesmql
subject.subjectregex_match[ng]-?[io]n .*deactiv6 rulesmql
subject.subjectregex_match[ng]-?[io]n .*disabl6 rulesmql
subject.subjectregex_matchabandon.*package6 rulesmql
subject.subjectregex_matchabout.your.account6 rulesmql
subject.subjectregex_matchacc(ou)?n?t (is )?on ho[li]d6 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

sender.email

#

Description

Message Data Model attribute: sender.email

Fields #

NameDescription
domain
domain.domainThe fully qualified domain name (FQDN). This may not *always* be routable, e.g. when an email address contains a domain that is just a TLD with no SLD, e.g. foo@WIN-bar
domain.root_domainThe root domain, including the TLD
domain.sldSecond-level domain, e.g. 'windows' for the domain 'windows.net'
domain.subdomainSubdomain, e.g. 'drive' for the domain 'drive.google.com'
domain.tldThe domain's top-level domain. E.g. the TLD of google.com is 'com'
domain.validWhether the domain is valid
emailFull email address
local_partLocal-part, i.e. before the @

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type.inboundeqtrue733 rulesmql
profile.by_senderfunc_callprofile.by_sender().any_messages_malicious_or_spam125 rulesmql
profile.by_senderfunc_callprofile.by_sender().prevalence in (new, outlier)35 rulesmql
attachmentslength_compare071 rulesmql
body.linkslength_compare065 rulesmql
body.linkslength_compare1039 rulesmql
recipients.tolength_compare151 rulesmql
recipients.tolength_compare036 rulesmql
headers.referenceslength_compare040 rulesmql
headers.in_reply_tois_null39 rulesmql
type.outboundeqtrue39 rulesmql
headers.auth_summary.dmarc.passeqtrue35 rulesmql
headers.auth_summary.spf.passeqtrue31 rulesmql
headers.reply_tolength_compare030 rulesmql
recipients.cclength_compare024 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #