Message Subject

Attribute groupRule
subjectY

subject

#

Description

Message Data Model attribute: subject

Fields #

NameDescription
baseSubject of the email with tags and reply/forward indicators removed
is_forwardIndicates if the subject of the email is a forward
is_replyIndicates if the subject of the email is a reply
subjectSubject of the email

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
type.inboundeqtrue282 rulesmql
type.outboundeqtrue149 rulesmql
attachmentslength_compare047 rulesmql
attachmentslength_compare114 rulesmql
body.linkslength_compare039 rulesmql
headers.in_reply_tois_null31 rulesmql
headers.referenceslength_compare031 rulesmql
profile.by_senderfunc_callprofile.by_sender().prevalence in (new, outlier)17 rulesmql
headers.reply_tolength_compare016 rulesmql
body.current_thread.textcontainssubscription15 rulesmql
body.current_thread.textcontainsantivirus13 rulesmql
body.current_thread.textcontainscancel13 rulesmql
body.previous_threadslength_compare015 rulesmql
headers.auth_summary.dmarc.passeqtrue15 rulesmql
headers.auth_summary.spf.passeqtrue14 rulesmql

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sublime MQL #

References #