AI-Generated Mass Phishing: High-Volume Near-Identical Subjects from New Domains (T1566.001)
This rule identifies potential mass phishing campaigns by monitoring O365 email activity for high-volume outbound mail from newly registered or observed domains. It specifically flags senders that have no prior historical activity in the last 90 days, have a domain age of less than 30 days, and exhibit a low variation in email subjects across a large volume of recipients, which is characteristic of automated bulk phishing.
Splunk (SPL)

