Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 28 additions & 0 deletions insights/headers/phishing_simulation_adaptive_security.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
name: "Adaptive Security phishing simulation"
type: "query"
source: |
type.inbound
and any(headers.hops,
any(.fields,
(.name == "X-Adaptive-Bypass" and .value == "adaptive")
or .name =~ "X-Adaptive-Campaign-Id"
)
)
and sender.email.domain.root_domain in (
"confirm-login.com",
"loginupdate.com",
"resetusername.com",
"logindirect.net",
"secureaccount.net",
"secureaccounts.net",
"resetpassword.io",
"secureaccounts.org",
"updateaccount.co",
"verifylogin.co",
"protect-sys.com",
"sys-info-net.com"
)
severity: "informational"
tags:
- "Headers"
- "Phishing simulation"
54 changes: 54 additions & 0 deletions insights/headers/phishing_simulation_arctic_wolf_msa.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
name: "Arctic Wolf MSA phishing simulation"
type: "query"
source: |
type.inbound
// Arctic Wolf MSA sends from shared SendGrid infrastructure, so the IP set
// alone is not specific; it must be paired with an Arctic Wolf campaign domain.
and any(headers.ips,
.ip in (
"149.72.89.230",
"149.72.154.143",
"149.72.233.38",
"149.72.61.155"
)
)
and (
sender.email.domain.root_domain in (
"arcticwolfawareness.com",
"arcticwolf.com",
"automated-mailsender.com",
"corporate-alert.com",
"helpdesk-itsupport.com",
"humanresources-mailer.com",
"internal-humanresources.com",
"internalcorporate-mailer.com",
"mail-donotreply.com",
"securityalert-corporate.com",
"admin-hinweis.de",
"itsupport-mitarbeiter.de",
"mitarbeiter-helpdesk.de",
"unternehmenssicherheit-alarm.de"
)
or any(body.links,
.href_url.domain.root_domain in (
"arcticwolfawareness.com",
"arcticwolf.com",
"automated-mailsender.com",
"corporate-alert.com",
"helpdesk-itsupport.com",
"humanresources-mailer.com",
"internal-humanresources.com",
"internalcorporate-mailer.com",
"mail-donotreply.com",
"securityalert-corporate.com",
"admin-hinweis.de",
"itsupport-mitarbeiter.de",
"mitarbeiter-helpdesk.de",
"unternehmenssicherheit-alarm.de"
)
)
)
severity: "informational"
tags:
- "Headers"
- "Phishing simulation"
49 changes: 49 additions & 0 deletions insights/headers/phishing_simulation_breach_secure_now.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
name: "Breach Secure Now phishing simulation"
type: "query"
source: |
type.inbound
and any(headers.ips,
.ip in (
"149.72.207.249",
"168.245.40.98",
"149.72.184.111",
"168.245.30.20",
"54.209.51.230",
"18.209.119.19",
"34.231.173.178",
"168.245.68.173",
"168.245.34.162"
)
)
and sender.email.domain.root_domain in (
"it-support.care",
"customer-portal.info",
"member-services.info",
"bankonlinesupport.com",
"secureaccess.biz",
"logineverification.com",
"iogmein.com",
"mlcrosoft.live",
"cloud-service-care.com",
"packagetrackingportal.com"
)
and any(headers.hops, any(.fields, .name =~ "X-SN-EMAIL-PHISHING"))
// every non-mailto link must point at a Breach Secure Now simulation domain
and all(filter(body.links, .href_url.scheme != "mailto"),
.href_url.domain.root_domain in (
"it-support.care",
"customer-portal.info",
"member-services.info",
"bankonlinesupport.com",
"secureaccess.biz",
"logineverification.com",
"iogmein.com",
"mlcrosoft.live",
"cloud-service-care.com",
"packagetrackingportal.com"
)
)
severity: "informational"
tags:
- "Headers"
- "Phishing simulation"
11 changes: 11 additions & 0 deletions insights/headers/phishing_simulation_bullphish.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
name: "BullPhish ID phishing simulation"
type: "query"
source: |
type.inbound
and headers.mailer == "Bullphish"
and any(headers.domains, .root_domain == "bullphish.com")
and any(headers.ips, .ip == "34.237.252.20")
severity: "informational"
tags:
- "Headers"
- "Phishing simulation"
31 changes: 31 additions & 0 deletions insights/headers/phishing_simulation_caniphish.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
name: "CanIPhish phishing simulation"
type: "query"
source: |
type.inbound
// CanIPhish stamps a dedicated header on every simulation (value is the
// per-tenant ID, so match on the header name). White-labeled tenants keep
// the header even when the sending domains are customized.
and any(headers.hops, any(.fields, .name =~ "X-CanIPhish"))
and (
any(headers.ips, .ip in ("3.106.21.22", "13.237.47.221"))
or sender.email.domain.root_domain in (
"alerting-services.com",
"authwebmail.com",
"cloud-notification-services.com",
"securesupportcloud.com",
"office-365-notifications.com",
"webnotifications.net",
"paypaypal.net",
"cmail31.com",
"authenticationsecure.com",
"verificationweb.net",
"onlineverify.net",
"portal-login.net",
"email-forwarder.net",
"caniphish.com"
)
)
severity: "informational"
tags:
- "Headers"
- "Phishing simulation"
13 changes: 13 additions & 0 deletions insights/headers/phishing_simulation_fable.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
name: "Fable Security phishing simulation"
type: "query"
source: |
type.inbound
and any(headers.ips, .ip in ("50.31.205.248", "159.183.27.69"))
and any(headers.hops,
any(.fields, .name =~ "X-Fable-Phishing-Simulation" and .value == "1")
)
and headers.auth_summary.dmarc.pass
severity: "informational"
tags:
- "Headers"
- "Phishing simulation"
64 changes: 64 additions & 0 deletions insights/headers/phishing_simulation_huntress.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
name: "Huntress phishing simulation"
type: "query"
source: |
type.inbound
and (
// SMTP delivery (single /32, equivalent to the exclusion's beta.ip_in)
any(headers.ips, .ip == "18.205.140.116")
// MS/Gmail DMI
or length(headers.hops) == 1
)
and any(headers.hops, any(.fields, .name =~ "X-PHISHTEST-Curricula"))
and any(headers.hops,
any(.fields, .name in~ ('X-C-Message-Id', 'C-Message-Id'))
)
and sender.email.domain.root_domain in (
"securitynotifications.org",
"security-updater.com",
"amazonsecurity.org",
"breach-notice.com",
"filesharingnow.com",
"mailbox-quota.com",
"passwordsnotification.com",
"securelinkedin.com",
"fraud-assistance.com",
"payment-process.com",
"news-article.com",
"invite-meeting.com",
"feedback-collect.com",
"businessnotice.org",
"databoxonline.com",
"electronic-hr.com",
"emailtransaction.com",
"employee-services.org",
"governmentnotice.org",
"notificationservices.org",
)
and any(body.links,
.href_url.domain.root_domain in (
"securitynotifications.org",
"security-updater.com",
"amazonsecurity.org",
"breach-notice.com",
"filesharingnow.com",
"mailbox-quota.com",
"passwordsnotification.com",
"securelinkedin.com",
"fraud-assistance.com",
"payment-process.com",
"news-article.com",
"invite-meeting.com",
"feedback-collect.com",
"businessnotice.org",
"databoxonline.com",
"electronic-hr.com",
"emailtransaction.com",
"employee-services.org",
"governmentnotice.org",
"notificationservices.org",
)
)
severity: "informational"
tags:
- "Headers"
- "Phishing simulation"
10 changes: 10 additions & 0 deletions insights/headers/phishing_simulation_infoseciq.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
name: "Infosec IQ phishing simulation"
type: "query"
source: |
type.inbound
and any(headers.ips, .ip in ("52.1.22.105", "34.202.49.109"))
and any(headers.domains, .domain == "securityiq.infosecinstitute.com")
severity: "informational"
tags:
- "Headers"
- "Phishing simulation"
10 changes: 10 additions & 0 deletions insights/headers/phishing_simulation_material.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
name: "Material phishing simulation"
type: "query"
source: |
type.inbound
and length(headers.hops) == 1
and strings.ends_with(headers.message_id, "material.security>")
severity: "informational"
tags:
- "Headers"
- "Phishing simulation"
Loading
Loading