Description
Recursively scans files and archives to detect LNK connection files.
LNK files can be weaponised to execute arbitrary commands including unpacking and running executable content embedded within the file itself.
References
type.inbound
and any(attachments,
.file_extension =~ "lnk"
or (
.file_extension in~ $file_extensions_common_archives
and any(file.explode(.), .file_extension =~ "lnk")
)
)
Playground
Test against your own EMLs or sample data.