type.inbound
// only one link to Figma
and length(distinct(filter(body.links,
.href_url.domain.root_domain in ("figma.com")
and strings.istarts_with(.href_url.path, "/deck")
),
.href_url.url
)
) == 1
and any(filter(body.links,
.href_url.domain.root_domain in ("figma.com")
and strings.istarts_with(.href_url.path, "/deck")
),
any(ml.nlu_classifier(beta.ocr(ml.link_analysis(.).screenshot).text).intents,
.name == "cred_theft" and .confidence in ("medium", "high")
)
)
and (
(
profile.by_sender().prevalence in ("new", "outlier")
and not profile.by_sender().solicited
)
or profile.by_sender().any_messages_malicious_or_spam
or profile.by_sender().days_since.last_contact > 30
)
and not profile.by_sender().any_messages_benign
Playground
Test against your own EMLs or sample data.