Sublime Security medium experimental mql
Credential phishing: AWS Lambda URL with recipient targeting
Detects messages containing AWS Lambda URLs with the recipient's email address embedded in the fragment, indicating potential abuse of AWS Lambda services for targeted malicious activities.
Detection Logic
type.inbound
and recipients.to[0].email.domain.sld == sender.email.local_part
and any(body.links,
strings.icontains(.href_url.domain.domain, "lambda-url")
and strings.icontains(.href_url.fragment, recipients.to[0].email.email)
) Field Validations
Loading…
Comments (0)
Loading comments...