Message Subject
| Attribute group | Rule |
|---|---|
| subject | Y |
subject
#Description
Message Data Model attribute: subject
Fields #
| Name | Description |
|---|---|
| base | Subject of the email with tags and reply/forward indicators removed |
| is_forward | Indicates if the subject of the email is a forward |
| is_reply | Indicates if the subject of the email is a reply |
| subject | Subject of the email |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
type.inbound | eq | true | 282 rules | mql |
type.outbound | eq | true | 149 rules | mql |
attachments | length_compare | 0 | 47 rules | mql |
attachments | length_compare | 1 | 14 rules | mql |
body.links | length_compare | 0 | 39 rules | mql |
headers.in_reply_to | is_null | | 31 rules | mql |
headers.references | length_compare | 0 | 31 rules | mql |
profile.by_sender | func_call | profile.by_sender().prevalence in (new, outlier) | 17 rules | mql |
headers.reply_to | length_compare | 0 | 16 rules | mql |
body.current_thread.text | contains | subscription | 15 rules | mql |
body.current_thread.text | contains | antivirus | 13 rules | mql |
body.current_thread.text | contains | cancel | 13 rules | mql |
body.previous_threads | length_compare | 0 | 15 rules | mql |
headers.auth_summary.dmarc.pass | eq | true | 15 rules | mql |
headers.auth_summary.spf.pass | eq | true | 14 rules | mql |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sublime MQL #