Sublime Security medium experimental mql

Truth Social infrastructure abuse via link redirect

Email contains a Truth Social link (links.truthsocial.com) but does not originate from a Truth Social domain. This is a known malicious tactic.

View Source

Detection Logic

type.inbound
and length(body.links) < 10
and any(body.links, .href_url.domain.domain == "links.truthsocial.com")
and sender.email.domain.domain not in~ ('truthsocial.com')
and (
  not profile.by_sender().solicited
  or (
    profile.by_sender().any_messages_malicious_or_spam
    and not profile.by_sender().any_messages_benign
  )
)
// negate highly trusted sender domains unless they fail DMARC authentication
and (
  (
    sender.email.domain.root_domain in $high_trust_sender_root_domains
    and not headers.auth_summary.dmarc.pass
  )
  or sender.email.domain.root_domain not in $high_trust_sender_root_domains
)

Field Validations

Loading…

Comments (0)

Loading comments...