Description

Detects inbound messages with an empty body that carry a PDF attachment referencing document portal or review invitation language alongside the recipient's own email address embedded in the file. The attachment content is further validated by an NLU classifier with high confidence for credential theft intent. Messages from highly trusted sender domains that pass DMARC authentication are excluded.

References

No references.

Sublime Security
Created Sep 18th, 2026 • Last updated Sep 18th, 2026
Source
type.inbound
and (body.current_thread.text == '' or body.current_thread.text is null)
and any(filter(attachments, .file_type == "pdf"),
        any(file.explode(.),
            strings.icontains(.scan.strings.raw,
                              "document portal",
                              "invited to review",
                              "confidential document"
            )
            // recipient's address inside attachment
            and any(recipients.to,
                    strings.icontains(..scan.strings.raw, .email.email)
            )
            and any(ml.nlu_classifier(.scan.strings.raw).intents,
                    .name == "cred_theft" and .confidence == "high"
            )
        )
)
// negate highly trusted sender domains unless they fail DMARC authentication
and not (
  sender.email.domain.root_domain in $high_trust_sender_root_domains
  and coalesce(headers.auth_summary.dmarc.pass, false)
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started