type.inbound
and (
(
// technique
strings.ilike(sender.display_name, "ukr*net")
and sender.email.domain.root_domain != "ukr.net"
)
or (
// IOCs
subject.subject == "Увага"
and (
sender.email.email in (
"muthuprakash.b@tvsrubber.com",
"rakesh.ict@msruas.ac.in",
"omars@salecharter.net",
"citi.in.pm@xerago.com",
"qs@gsengint.com",
"sec.ls@msruas.ac.in",
"vaishnavi.kj@tvsrubber.com",
"nshcorp@nshcorp.in",
"purchase2@hitechelastomers.com",
"productionbelgavi@hodekindia.com",
"narayanababu.py.ph@msruas.ac.in",
"roopa.tsld@msruas.ac.in",
"in-nonciti.basupport@xerago.com",
"info@empiink.com",
"pooja.fa@msruas.ac.in",
"babu.d@tvsrubber.com",
"systeam@xerago.com",
"dean.ds@msruas.ac.in",
)
or any(body.links, .href_url.domain.domain == "consumerspanel.frge.io")
)
)
)
Playground
Test against your own EMLs or sample data.