type.inbound
and (body.current_thread.text == '' or body.current_thread.text is null)
and any(filter(attachments, .file_type == "pdf"),
any(file.explode(.),
strings.icontains(.scan.strings.raw,
"document portal",
"invited to review",
"confidential document"
)
// recipient's address inside attachment
and any(recipients.to,
strings.icontains(..scan.strings.raw, .email.email)
)
and any(ml.nlu_classifier(.scan.strings.raw).intents,
.name == "cred_theft" and .confidence == "high"
)
)
)
// negate highly trusted sender domains unless they fail DMARC authentication
and not (
sender.email.domain.root_domain in $high_trust_sender_root_domains
and coalesce(headers.auth_summary.dmarc.pass, false)
)
Playground
Test against your own EMLs or sample data.