Detects inbound messages where the sender's display name ends with a 'cc:' or 'CC:' suffix, a tactic often used to appear as though they're recipients rather than part of the attacker's sender identity.
References
No references.
Sublime Security
Created Sep 16th, 2026 • Last updated Sep 16th, 2026