type.inbound
and any(attachments, strings.icontains(.file_name, "eicar"))
and any(attachments,
any(file.explode(.),
any(.scan.strings.strings,
strings.icontains(.,
'X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*'
)
)
)
)
Playground
Test against your own EMLs or sample data.