Detection of Executive Email Impersonation and Admin-Sounding Cloud Account Creation

This rule monitors for two distinct suspicious activities: 1) Inbound emails where the sender display name matches a list of executive titles, commonly indicative of Business Email Compromise (BEC) or executive impersonation attacks; 2) The creation of cloud service accounts with names mimicking administrative or IT support roles, which may indicate an adversary establishing persistent, privileged access.