Phishing email with HTML/XHTML/SVG/QR attachment mimicking contract or benefits review from mass-mailing infrastructure
This rule monitors for incoming emails containing suspicious attachments (such as .htm, .xhtml, .svg, or QR codes) associated with common business-related subject lines or file names (e.g., 'contract', 'agreement', 'edocs'). It specifically identifies emails originating from 'amazonses.com' that do not match expected trusted domains like DocuSign or Workday, indicating a potential credential harvesting or phishing attempt.
Microsoft Sentinel (KQL)

