Potential Spear Phishing Campaign Detection

This rule detects potential spear phishing campaigns by identifying a high volume of emails (10 or more within an hour) from external senders (not @company.com) that contain keywords like 'password', 'account', or 'security' in the subject line, and also include either an attachment or a URL. This combination of factors suggests a targeted social engineering attempt.