sublime
medium
mql
Attachment: Image-only docx/pptx callback phishing
Detects inbound emails with docx or pptx attachments that contain no text but exactly one embedded image, a common tactic to evade text-based scanning by presenting content as a picture. The rule then inspects any extracted text from the image for a combination of callback phishing lures—such as references to subscriptions, invoices, refunds, or antivirus renewals alongside phone numbers or dollar amounts—paired with impersonation of well-known brands like PayPal, McAfee, Norton, or Best Buy, in